ip.airdropsalert[.]click
Forensic brief
PhishDestroy identifies ip.airdropsalert.click as a high-risk crypto drainer domain designed to steal digital assets by exploiting unsuspecting users. The domain masquerades as an airdrop alert site, a common lure in the crypto community, to trick users into connecting wallets and unknowingly draining their funds. This kind of threat matters because it directly compromises users’ cryptocurrency holdings, potentially resulting in significant financial losses. The domain was registered through Dynadot LLC on October 1, 2025 and resolved to IP address 104.21.40.55. It was flagged by 12 out of 95 security vendors on VirusTotal and appeared on two known security blocklists before being taken offline. The phishing infrastructure used the Angel Drainer kit, a recognized crypto wallet stealer, enhancing its effectiveness in siphoning tokens from connected wallets. Although the domain is currently offline, its prior activity highlights the ongoing risk posed by such scam domains using professional tools. Users are strongly advised to avoid interacting with ip.airdropsalert.click and any suspicious airdrop-related websites. Never connect cryptocurrency wallets to unfamiliar or unverified sites, and use hardware wallets or trusted wallet apps with strong security measures. Regularly review wallet permissions and revoke any suspicious or unused access. Staying informed through resources like PhishDestroy can help users recognize and evade emerging crypto scams effectively.
Threat response pipeline
Cloudflare Radar
VirusTotal
Forensic Evidence CollectionEvidence capture
Domain Intelligence
Dynadot LLC
Technical details
Public blocklist status
Technologies
Technologies · 3 identified
VirusTotal consensus
Aggregated detection across 12 security vendors.
Evidence & external reports
Were you affected by this site?
Were You Affected?
Report to your local authorities
Email template — registrar abuse
abuse@dynadot.com
Registrar: Dynadot LLC Case: PD-
Embed this report
About this report
About this report: ip.airdropsalert.click
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 12 security vendors on VirusTotal and 3 public blocklists.
The site displays a page titled “ip Airdrop | Airdrop Alert”.
ip.airdropsalert.click has been flagged by 12 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.