# ieo-phantomwala.pages.dev — MALICIOUS — Crypto Drainer (Solana Drainer) > ieo-phantomwala.pages.dev uses a Solana drainer kit to steal crypto wallets. Act now to protect your assets. Learn how to stay safe. ## Summary PhishDestroy identifies ieo-phantomwala.pages.dev as a high-risk domain linked to crypto wallet draining. Although VirusTotal shows zero detections, the domain is active and appears in multiple security blocklists, signaling ongoing suspicious activity. This phishing site employs a Solana drainer kit designed to trick users into revealing private keys or seed phrases. By masquerading as a legitimate service, it aims to silently drain victims' crypto assets once they engage. If you visited this domain, immediately avoid entering any sensitive information. Run a full security scan, update your wallet credentials, and monitor your accounts for unauthorized transactions. Reporting the site to your platform provider can help protect others. ## Threat Details - Verdict: MALICIOUS — Crypto Drainer (Solana Drainer) - Site status: dead (HTTP 403) - Drainer type: Solana Drainer - Target brand: Phantom - Page title: Suspected phishing site | Cloudflare ## Domain Intelligence - Registered: 2026-03-08 19:07:01 - Registrar: Cloudflare, Inc. - Country: US - IP: 172.66.46.254 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: sid.ns.cloudflare.com tiffany.ns.cloudflare.com - SSL Issuer: Google Trust Services / WE1 ## Detection Status - VirusTotal: 5 vendors flagged Vendors: ["ADMINUSLabs", "ChainPatrol", "alphaMountain.ai", "Fortinet", "Phishing Database"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "MetaMask"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019ccea2-9781-732f-8d6e-9bd53c6f19ad.png - Cloudflare Radar: https://radar.cloudflare.com/scan/55ffcf47-74fc-413a-ae65-655d62bd3077 - Wayback Machine: https://web.archive.org/web/https://ieo-phantomwala.pages.dev - PhishDestroy: https://phishdestroy.io/domain/ieo-phantomwala.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/ieo-phantomwala.pages.dev/llm.txt ## If You Visited This Site 1. Revoke all token approvals immediately (revoke.cash / unrekt.net) 2. Move remaining funds to a new wallet 3. Do not interact with any transactions from this site 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/ieo-phantomwala.pages.dev/ Last updated: 2026-03-19