# jupiter-solana.network — MALICIOUS — Crypto Drainer (Solana Drainer) > Phishing site jupiter-solana.network impersonates Jupiter to drain Solana wallets. Avoid interaction and secure your assets now. ## Summary PhishDestroy identifies jupiter-solana.network as a high-risk crypto drainer phishing domain impersonating the legitimate Jupiter brand. The domain’s page title is deceptively labeled 'Instant | Jupiter' to lure victims seeking quick transactions. It specifically targets users of the Solana blockchain by deploying a Solana Drainer kit designed to steal private keys and drain crypto assets. Technically, jupiter-solana.network resolved to IP address 188.114.96.3 and was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. Google Safe Browsing flagged the domain for social engineering, and it appeared on three separate security blocklists. VirusTotal analysis showed 10 out of 95 security vendors detected malicious activity associated with this domain, reinforcing its credibility as a threat actor in the crypto space. Currently, the domain is offline, preventing further exploitation. This takedown reduces immediate risk but vigilance is advised as threat actors often re-register or migrate to new domains. Users should remain cautious of phishing attempts impersonating Jupiter and ensure wallet security by avoiding suspicious links and enabling multi-factor authentication. ## Threat Details - Verdict: MALICIOUS — Crypto Drainer (Solana Drainer) - Site status: dead (HTTP 403) - Drainer type: Solana Drainer - Target brand: Jupiter - Page title: Instant | Jupiter ## Domain Intelligence - Registrar: NiceNIC International Group Co., Limited - Country: HK - IP: 188.114.96.3 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: lynn.ns.cloudflare.com walk.ns.cloudflare.com - SSL Issuer: none ## Detection Status - VirusTotal: 10 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "BitDefender", "CyRadar", "Forcepoint ThreatSeeker", "Fortinet", "G-Data", "Google Safebrowsing", "Sophos", "Webroot"] - Google Safe Browsing: FLAGGED - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://urlscan.io/screenshots/01993406-4714-718b-b380-091c94cfc7d1.png - Cloudflare Radar: https://radar.cloudflare.com/scan/be01bb07-57ca-456b-930b-bf049545d2b7 - PhishDestroy: https://phishdestroy.io/domain/jupiter-solana.network/ - LLM endpoint: https://phishdestroy.io/domain/jupiter-solana.network/llm.txt ## If You Visited This Site 1. Revoke all token approvals immediately (revoke.cash / unrekt.net) 2. Move remaining funds to a new wallet 3. Do not interact with any transactions from this site 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/jupiter-solana.network/ Last updated: 2026-03-19