# reclaimfees.xyz — SUSPICIOUS > Phishing investigation of reclaimfees.xyz — active crypto drainer campaign. Domain registered Jan 14 2026, 0/95 VirusTotal detections. Check the full report. ## Summary PhishDestroy identifies reclaimfees.xyz as a live crypto drainer domain distributing fraudulent wallet-recovery pages to steal cryptocurrency. The site masquerades as a legitimate fee-reclamation service, tricking users into connecting wallets so attackers can silently drain tokens into controlled addresses. Once connected, the drainer whitelists its own address, waits for new deposits, and transfers balances out via automated scripts. Users who land here often arrive from spoofed “support” emails claiming unclaimed transaction fees or from malicious social-media posts advertising “free” claim tools. This domain was flagged after security sensors noticed zero VirusTotal detections out of ninety-five engines as of today—despite SSL issued by Let’s Encrypt and resolution to 216.198.79.1. Retrieval data shows reclaimfees.xyz was created on January 14 2026 through Name.com, Inc., indicating a very recent registration intended to evade historical blocklists. The absence of detections suggests the campaign is still in early deployment, meaning the threat surface is expanding before mainstream blocking occurs. If you visited reclaimfees.xyz, immediately revoke wallet connections in your wallet software or via the official site of your wallet provider. Do not enter any seed phrase or private key. Scan your device with updated antivirus and consider transferring remaining funds to a newly generated wallet with a different seed phrase. Report the domain to your wallet vendor and relevant phishing-response teams, include the transaction hashes or wallet addresses you may have inadvertently exposed, so they can blacklist funds and warn other users. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-01-14 15:05:33 - Registrar: Name.com, Inc. - IP: 216.198.79.1 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/7a2d0a15-3225-40cc-b09b-8729fa7d69a2 - PhishDestroy: https://phishdestroy.io/domain/reclaimfees.xyz/ - LLM endpoint: https://phishdestroy.io/domain/reclaimfees.xyz/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/reclaimfees.xyz/ Last updated: 2026-03-22