jup-s3[.]pw
jup-s3.pw is a domain used for brand impersonation of the Jupiter cryptocurrency project in phishing campaigns. The specific threat it poses involves attempts to deceive users into revealing sensitive information or approving malicious transactions. Although the site is currently taken offline it previously carried an elevated risk level.
Technical indicators for jup-s3.pw include detections by 2 of 95 VirusTotal vendors including Gridinsoft and SOCRadar along with a Gridinsoft trust score of 0/100. The domain created February 21, 2026 resolves to IP address 172.67.186.186 in the US under AS13335 Cloudflare, Inc. and appears on 3 security blocklists Blocked by PhishDestroy, MetaMask, SEAL. The SSL certificate was issued by WE1 and the page title observed was Just a moment...
Users who may have interacted with jup-s3.pw should revoke any token approvals and move funds to a new wallet address. For any credential exposure change passwords and enable two-factor authentication while monitoring accounts for fraudulent activity. Report the phishing domain to relevant authorities and blocklist maintainers.
Threat Response Pipeline
Public Blocklist Status
Forensic Intelligence
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive