# onexweb3.com — SUSPICIOUS > PhishDestroy identifies onexweb3.com as a fake Web3 wallet phishing site. VirusTotal 0/95 detections. Check the full report. ## Summary PhishDestroy identifies onexweb3.com as an active fake Web3 wallet phishing domain designed to deceive users into entering their cryptocurrency wallet credentials or private keys. This domain mimics legitimate Web3 wallet interfaces, such as MetaMask or Phantom, to trick victims into connecting their wallets or approving fraudulent transactions. Security researchers have flagged this domain for hosting phishing pages that harvest sensitive wallet data, including seed phrases and private keys, which are then used to drain cryptocurrency funds. The threat actor behind this campaign appears to be leveraging the growing popularity of Web3 technologies to lure unsuspecting users into compromising their digital assets. This domain was flagged with the following indicators: registered through GoDaddy.com, LLC, resolving to IP 65.1.234.58, and secured with a Let's Encrypt SSL certificate. The domain was created on January 11, 2026, and currently shows 0 detections on VirusTotal out of 95 scanners, indicating it has not yet been widely recognized by security vendors. Despite the lack of detections, the domain's recent creation date and suspicious infrastructure suggest it is part of an emerging phishing campaign. Users are advised to avoid interacting with this domain and to report any suspicious activity to their security teams or trusted cybersecurity platforms. If you have visited onexweb3.com or entered any credentials, immediately disconnect your wallet from the site, revoke any unauthorized connections, and transfer remaining funds to a new wallet. Enable multi-factor authentication (MFA) where possible and scan your devices for malware. Report the domain to PhishDestroy or your organization’s security team to help mitigate further risks. Stay vigilant for similar domains mimicking Web3 wallet services and always verify URLs before entering sensitive information. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-01-11 17:36:54 - Registrar: GoDaddy.com, LLC - IP: 65.1.234.58 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/80f73d6e-0f97-4097-8cf4-29e11f30e2c1 - PhishDestroy: https://phishdestroy.io/domain/onexweb3.com/ - LLM endpoint: https://phishdestroy.io/domain/onexweb3.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/onexweb3.com/ Last updated: 2026-03-30