# freegift-pump.fun — MALICIOUS > Domain freegift-pump.fun hosts a crypto drainer impersonating Pump.fun. Verify legitimacy on PhishDestroy before interacting. Resolves to IP 188.114.96. ## Summary PhishDestroy identifies freegift-pump.fun as an active crypto drainer impersonating the Solana-based token launch platform Pump.fun. This elevated-risk domain leverages brand impersonation to deceive users into connecting crypto wallets and signing malicious transactions. The threat actor behind this campaign capitalizes on Pump.fun's popularity to distribute wallet-draining malware, potentially resulting in irreversible asset theft. Users should exercise extreme caution when encountering this domain or associated links. This domain was flagged by PhishDestroy on February 24, 2026, and exhibits multiple red flags consistent with malicious activity. VirusTotal analysis shows 5 out of 95 security vendors flagging this domain as malicious, with a detection rate of 5.3%. The domain is registered through NameSilo, LLC and resolves to IP address 188.114.96.3, which hosts multiple suspicious domains. The SSL certificate, issued by Let's Encrypt, provides a false sense of security as it only verifies domain ownership, not the legitimacy of the service. The domain's recent creation date and lack of historical trust signals further indicate its malicious nature. While not currently listed on major blocklists, the combination of these factors suggests an evolving threat that may expand its footprint in the coming weeks. To mitigate exposure to this crypto drainer, users must verify any Pump.fun-related links or promotions through PhishDestroy's threat intelligence platform before taking action. Never connect your crypto wallet or sign transactions from unsolicited links, even if they appear to originate from Pump.fun. Implement wallet restrictions to limit transaction approvals to trusted domains only. Report any interactions with freegift-pump.fun to PhishDestroy immediately. For organizations, consider adding this domain and IP address to your network blocklists and educating users about the specific tactics used in crypto drainer campaigns. Maintain updated wallet software with transaction simulation features enabled to detect malicious contract interactions before approval. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) - Target brand: Pump.fun ## Domain Intelligence - Registered: 2026-02-24 12:58:42 - Registrar: NameSilo, LLC - IP: 188.114.96.3 ## Detection Status - VirusTotal: 5 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/70a5d643-4704-4832-893d-ec971ed0c77c - PhishDestroy: https://phishdestroy.io/domain/freegift-pump.fun/ - LLM endpoint: https://phishdestroy.io/domain/freegift-pump.fun/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/freegift-pump.fun/ Last updated: 2026-03-22