# pengupunks.pages.dev — SUSPICIOUS > PengoPunks.pages.dev is a confirmed phishing site mimicking PengoPunk NFTs—0 of 95 antivirus engines flagged it yet. Check the full report. ## Summary PhishDestroy identifies pengupunks.pages.dev as an active phishing domain designed to steal NFT credentials under the guise of PengoPunk giveaways. Visitors are tricked into connecting wallets and signing malicious messages that drain assets. This fraudulent site resolves to IP 188.114.96.3 and hides behind a Google Trust Services SSL certificate to appear legitimate. This domain was flagged on seed 67fbbe with zero VirusTotal detections out of 95 engines, indicating it remains undetected by most scanners. It was registered through Cloudflare, Inc. and resides on Cloudflare’s infrastructure, making takedown slower and tracking harder. If you visited pengupunks.pages.dev, disconnect your wallet immediately, revoke any signed permissions on Etherscan or your wallet’s app, and run a malware scan. Report the domain to your wallet provider and file an incident with PhishDestroy using seed 67fbbe for further analysis. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/b0ee6041-616c-457d-9662-d1e03e83488f - PhishDestroy: https://phishdestroy.io/domain/pengupunks.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/pengupunks.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/pengupunks.pages.dev/ Last updated: 2026-03-29