# pocketchange-staging.pages.dev — SUSPICIOUS > PhishDestroy warns that pocketchange-staging.pages.dev is a verified crypto drainer stealing crypto wallets after login. Only 0/95 VirusTotal detections so far. ## Summary PhishDestroy identifies pocketchange-staging.pages.dev as an active crypto drainer site designed to steal digital assets from wallets after users enter their credentials. This staging domain mimics legitimate services and aggressively redirects stolen funds to attacker-controlled addresses, making it particularly dangerous for cryptocurrency holders. This domain was flagged with 0 detections out of 95 VirusTotal scans, registered through Cloudflare on June 12, 2024, and resolving to IP 172.66.44.214 using a Google Trust Services SSL certificate. Despite the low detection rate, behavioral analysis confirms it operates as a crypto drainer that drains EVM wallets connected to the site. If you visited this site, immediately revoke wallet permissions, transfer remaining funds to a new wallet, and scan your device for malware. Report this domain to PhishDestroy for immediate blocking and share transaction hashes if funds were stolen to aid recovery efforts. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.44.214 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/841e7b99-ab80-439c-a968-e5e8d753b401 - PhishDestroy: https://phishdestroy.io/domain/pocketchange-staging.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/pocketchange-staging.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/pocketchange-staging.pages.dev/ Last updated: 2026-04-01