nanowallet[.]network
“Nano Wallet | Secure MPC Self-Custody Crypto Wallet”
The domain nanowallet.network is currently under investigation as a crypto drainer. The domain is offline and appears to be impersonating a legitimate cryptocurrency wallet service. Analysis indicates that the threat is not yet widely recognized, as it has been flagged by 0 of 95 VirusTotal vendors.
Infrastructure analysis reveals that the domain is registered through NameSilo, LLC, and resolves to the IP address 146.70.41.164. The domain was created on May 11, 2026, and it appears on 1 security blocklist, suggesting some level of suspicion or malicious activity. The SSL certificate is issued by Let's Encrypt, which is a common practice for both legitimate and malicious sites to establish a secure connection.
Given the current status of the domain as offline, the immediate threat is mitigated. However, the domain's presence on a security blocklist and its registration through a known registrar indicate a potential risk. It is recommended that all users avoid visiting this domain and report any related suspicious activity to their security teams. Organizations should consider adding this domain to their firewall blocklists and monitoring for any associated IP addresses or subdomains. Further investigation is warranted to determine the full scope of the threat and any associated malicious activities.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive