MALICIOUS — CRITICAL
hashpackweb3-wallet[.]created[.]app
Analysis as of July 24, 2026 indicates that the domain hashpackweb3-wallet.created.app is actively hosting a crypto-drainer operation.
- VirusTotal
- 0/91
- Blocklists
- 2 · MetaMask, SEAL
- Availability
- Content unavailable · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
Evidence Analysis
Analysis as of July 24, 2026 indicates that the domain hashpackweb3-wallet.created.app is actively hosting a crypto-drainer operation. The domain was registered through the Created App service, and its authoritative name server information is not publicly available (NS_NOT_FOUND). DNS resolution returns the IPv4 address 216.150.16.129, which is the sole hosting endpoint observed. The IP address has not been linked to known hosting providers or cloud services in the available data, and no additional infrastructure such as CDN or reverse-proxy layers have been identified. The domain appears on a single security blocklist and is currently listed as blocked by PhishDestroy, confirming that at least one reputable anti‑phishing feed has flagged the host.
No other public blocklists or reputation services are reported. A VirusTotal scan performed by 91 vendors returned no detections, but the absence of a match does not constitute a safety assurance and should be interpreted as a lack of current signatures rather than a clean bill of health. Because the page title, SSL certificate details, HTTP response codes, and any observed content are not provided, the exact phishing landing page cannot be described. Consequently, the specific tactics used to lure victims—whether through deceptive URLs, social engineering messages, or compromised accounts—remain uncertain. However, the classification as a crypto-drainer suggests that the site likely attempts to trick users into transferring cryptocurrency assets to addresses controlled by the threat actor.
Defenders should prioritize the following actions: add 216.150.16.129 to network-level deny lists and configure DNS filtering to block hashpackweb3-wallet.created.app. Monitor outbound traffic for attempts to contact the domain or resolve its IP, especially from endpoints that handle cryptocurrency wallets.
Data coverage12 recorded checks
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: created.app
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain created.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 9 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% confidenceReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% confidenceVercel is a cloud platform for static frontends and serverless functions.
vercel.com 100% confidenceNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% confidenceLaunchDarkly is a continuous delivery and feature flags as a service platform that integrates into a company's current development cycle.
launchdarkly.com 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceCloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com 100% confidenceVirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of hashpackweb3-wallet.created.app · checked Jul 24, 2026
Evidence & External ReportsIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.