h3-wallet[.]com
Phishing and security check for h3-wallet.com
“H3 Wallet — Crypto made simple”
Evidence Analysis
Analysis as of August 04, 2026 indicates that h3-wallet.com is actively used as a crypto-drainer infrastructure. The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy mitigation service, confirming that it has been observed delivering malicious activity against cryptocurrency users. A VirusTotal query shows the domain was examined by 91 distinct scanning engines; at the time of the query none of those engines reported a detection, which does not constitute a safety assurance given the active classification.
No public WHOIS registration details, hosting IP, or SSL certificate information have been disclosed in the supplied intelligence, limiting deeper infrastructure profiling. The threat type is identified as a crypto drainer, suggesting that the site likely attempts to harvest private keys, seed phrases, or transaction credentials to exfiltrate funds. Risk level remains under investigation, and the operational status is marked as active.
Defenders should add h3-wallet.com to deny-list rules across DNS filtering, proxy, and endpoint protection solutions, and monitor network traffic for attempts to resolve or contact the domain. Incident response teams should treat any credential submissions to the site as compromised and advise affected users to rotate keys and revoke any potentially exposed assets. Continuous re-evaluation is recommended as additional telemetry becomes available.
Data coverage12 recorded checks
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | h3-wallet.com |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of h3-wallet.com · checked Aug 4, 2026
Evidence & External ReportsIndependent lookups and source reports
PD-20260804-A65AD0 Recipient: abuse@ownregistrar.com Victim safety and official reportingImmediate actions and verified reporting channels
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.