# monero-chan.finance — MALICIOUS — Crypto Drainer (Solana Drainer) > Discover if monero-chan.finance is safe or a scam. Learn about its crypto drainer activity and offline status before engaging with $MONEROCHAN tokens. ## Summary PhishDestroy identifies monero-chan.finance as a medium-risk crypto drainer domain associated with deceptive airdrop campaigns promising free $MONEROCHAN tokens. The domain is classified as malicious due to its use in illicit crypto asset draining activities, specifically targeting users through an AI robot training airdrop lure. Technical indicators reveal that monero-chan.finance resolved to IP 37.1.215.40 and was registered recently in November 2025 via NiceNIC International Group. The domain appeared on two security blocklists and was flagged by 6 out of 95 VirusTotal scanners. The underlying drainer infrastructure utilized a Solana Drainer kit, which is known for siphoning crypto assets from victims’ wallets. These factors contribute to the domain's medium threat level. Currently, monero-chan.finance is offline, indicating that it has been taken down or disabled, reducing immediate risk to users. However, its previous activity and the presence on blocklists warrant caution. Users should avoid interacting with this domain or similar airdrop offers to prevent potential loss of cryptocurrency. PhishDestroy recommends vigilance in recognizing such schemes and verifying legitimacy before participation. ## Threat Details - Verdict: MALICIOUS — Crypto Drainer (Solana Drainer) - Site status: dead (HTTP 403) - Drainer type: Solana Drainer - Scam type: Airdrop Scam - Kit: Airdrop Scam - Page title: Airdrop is live! | Join our exclusive airdrop campaign and earn free $MONEROCHAN tokens by participating in AI robot training. Limited time opportunity to claim your rewards! ## Domain Intelligence - Registered: 2025-11-09 00:00:00 - Expires: 2026-11-09 00:00:00 - Registrar: NiceNIC International Group Co., Limited - Country: HK - IP: 37.1.215.40 - IP Country: US - IP City: Chicago - IP Org: AS29802 HIVELOCITY, Inc. - Nameservers: ns3.my-ndns.com ns4.my-ndns.com - SSL Issuer: none ## Detection Status - VirusTotal: 6 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "CyRadar", "Fortinet", "Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "MetaMask"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019a9277-23c4-77df-8f32-3d1d51f488ba.png - Cloudflare Radar: https://radar.cloudflare.com/scan/5b3036c6-b047-40b6-9a2b-f574a4a249a9 - Wayback Machine: https://web.archive.org/web/https://monero-chan.finance - PhishDestroy: https://phishdestroy.io/domain/monero-chan.finance/ - LLM endpoint: https://phishdestroy.io/domain/monero-chan.finance/llm.txt ## If You Visited This Site 1. Revoke all token approvals immediately (revoke.cash / unrekt.net) 2. Move remaining funds to a new wallet 3. Do not interact with any transactions from this site 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/monero-chan.finance/ Last updated: 2026-03-19