# merklel.xyz — SUSPICIOUS > merklel.xyz crypto drainer has zero detections on VirusTotal (0/95) and targets MetaMask users. Block phishing now before digital assets are drained. ## Summary PhishDestroy identifies merklel.xyz as a live crypto drainer impersonating MetaMask to steal users’ wallet credentials and drain crypto balances. merklel.xyz resolves to IP 188.114.96.3 via a Let’s Encrypt SSL certificate and was registered on April 01, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED. VirusTotal currently shows 0/95 detections and the domain appears on 2 public security blocklists. MetaMask and SEAL already block the site, confirming malicious intent despite low antivirus coverage. If you clicked or entered wallet details on this domain, immediately disconnect any connected wallets, revoke any approved permissions in your wallet settings, transfer remaining funds to a new wallet, and scan your device with updated antivirus software. Never reuse passwords and enable hardware wallet signing for future transactions to reduce risk. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-04-01 11:05:46 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["MetaMask", "SEAL"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/merklel.xyz - PhishDestroy: https://phishdestroy.io/domain/merklel.xyz/ - LLM endpoint: https://phishdestroy.io/domain/merklel.xyz/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/merklel.xyz/ Last updated: 2026-04-07