# proposals-ethena.finance — SUSPICIOUS > proposals-ethena.finance is a crypto drainer imposter (VirusTotal: 0/95) mimicking Ethena. Avoid interactions immediately. ## Summary PhishDestroy identifies proposals-ethena.finance as an active crypto drainer domain impersonating Ethena, a legitimate cryptocurrency protocol. This deceptive site lures users into connecting their crypto wallets under false pretenses, aiming to drain digital assets directly. The domain was flagged by ScamSniffer and is under investigation due to its malicious intent and recent establishment as a credential theft tool. This domain poses a significant risk to cryptocurrency users, particularly those familiar with Ethena. VirusTotal currently shows 0/95 detections, indicating low detection by antivirus engines, while security researchers have identified its association with credential theft tactics. Registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on April 06, 2026, it resolves to IP 188.114.96.3 and appears on 1 security blocklist, with a Let's Encrypt SSL certificate adding a veneer of legitimacy. Its recent creation (April 2026) suggests a hastily deployed threat designed to exploit trust in the Ethena brand before widespread detection. Users who visited proposals-ethena.finance should immediately disconnect their wallets from the site, revoke any connected permissions via their wallet's app or interface, and scan their devices for malware. Avoid entering any credentials or wallet connections on this domain. Report the site to ScamSniffer and your wallet provider if interactions occurred. Monitor crypto wallets for unauthorized transactions and consider transferring assets to a cold wallet if suspicious activity is detected. Never reuse passwords or private keys across platforms to mitigate credential theft risks. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-04-06 16:52:16 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["ScamSniffer"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/proposals-ethena.finance - PhishDestroy: https://phishdestroy.io/domain/proposals-ethena.finance/ - LLM endpoint: https://phishdestroy.io/domain/proposals-ethena.finance/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/proposals-ethena.finance/ Last updated: 2026-04-06