# publicsale.well3.website — MALICIOUS — Crypto Drainer (Ice Phishing) > publicsale.well3.website is a confirmed phishing domain operating in the crypto space. Our automated scanners detected wallet-draining capabilities on this site. This domain has been flagged and added to global threat intelligence feeds. ## Summary Threat Overview The domain publicsale.well3.website has been identified as a cryptocurrency phishing website. This malicious site targets Web3 users by mimicking legitimate crypto platforms to steal wallet credentials and digital assets. Attack Analysis Phishing sites in the cryptocurrency space commonly employ wallet-draining techniques, fake token approval requests, and seed phrase harvesting to steal digital assets from unsuspecting victims. Risk Indicators - Domain registered on website TLD - Contains cryptocurrency-related keywords - Domain length: 24 characters - Uses a TLD frequently associated with malicious domains - Contains numbers in the domain name, often seen in phishing - Drainer Detected Protection Tips Always verify URLs before connecting your wallet. Use bookmarks for frequently visited crypto platforms. Enable transaction simulation tools to preview what you're signing. ## Threat Details - Verdict: MALICIOUS — Crypto Drainer (Ice Phishing) - Site status: dead (HTTP 403) - Drainer type: Ice Phishing - Page title: WELL3 ## Domain Intelligence - Expires: 2037-12-31 23:55:55 - Registrar: arin - Country: US - IP: 2606:4700:3034::ac43:c909 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: 1 - SSL Issuer: none ## Detection Status - VirusTotal: 0 vendors flagged Vendors: [] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "ScamSniffer"] ## Evidence - Screenshot: https://urlscan.io/screenshots/169d0980-eda0-46c3-a1f1-b6d473b6514d.png - Cloudflare Radar: https://radar.cloudflare.com/scan/3c0abe3a-d6f9-4405-9cc9-b83a4831df11 - PhishDestroy: https://phishdestroy.io/domain/publicsale.well3.website/ - LLM endpoint: https://phishdestroy.io/domain/publicsale.well3.website/llm.txt ## If You Visited This Site 1. Revoke all token approvals immediately (revoke.cash / unrekt.net) 2. Move remaining funds to a new wallet 3. Do not interact with any transactions from this site 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/publicsale.well3.website/ Last updated: 2026-03-19