# nodewallets.pages.dev — SUSPICIOUS > nodewallets.pages.dev is a crypto drainer posing as a wallet site. VirusTotal shows 0/95 detections. Verify safety on PhishDestroy immediately. ## Summary PhishDestroy identifies nodewallets.pages.dev as an active crypto drainer scam site designed to steal cryptocurrency from unsuspecting users. The domain mimics legitimate wallet interfaces to trick victims into connecting their digital assets to fraudulent smart contracts that silently drain funds. Crypto drainers like this exploit browser wallet extensions (e.g., MetaMask) by prompting users to sign malicious transactions that authorize fund transfers to attacker-controlled addresses. Once connected, these sites can execute multiple drain operations without requiring additional approvals, resulting in irreversible financial losses. This domain was flagged by PhishDestroy’s automated threat intelligence pipeline using seed identifier 5c8c12. VirusTotal analysis reveals 0 detections out of 95 security vendors, indicating it remains under the radar of mainstream detection systems. The domain was registered through Cloudflare, Inc. and resolves to IP address 172.66.47.43, which is part of Cloudflare’s edge network infrastructure. The SSL certificate is issued by Google Trust Services, a detail attackers often use to appear legitimate. These technical indicators suggest this is an emerging threat that hasn’t yet been widely categorized by security tools. If you visited nodewallets.pages.dev or connected your wallet to this site, immediately revoke all connected wallet permissions through your wallet extension’s connection settings. Use blockchain explorers like Etherscan or BscScan to check for suspicious outgoing transactions. Do not interact with any further prompts from this domain. Report the incident to PhishDestroy using the seed identifier 5c8c12 to help improve detection for others. Consider transferring remaining funds to a new wallet with a different seed phrase and enable additional security measures like hardware wallets and transaction simulation tools. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.43 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/1a858d0f-49b9-4a24-a080-5dd8abcb2dfc - PhishDestroy: https://phishdestroy.io/domain/nodewallets.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/nodewallets.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/nodewallets.pages.dev/ Last updated: 2026-03-28