rewards-ssv[.]network
Evidence Summary
The domain rewards-ssv.network is currently active and classified as a high-risk crypto wallet drain phishing site. Analysis indicates the domain specifically targets users of the SSV Network decentralized staking protocol by presenting fraudulent reward claims or airdrop interfaces designed to harvest private keys or seed phrases. The site remains operational and continues to pose a direct threat to cryptocurrency holders interacting with SSV-related services. Infrastructure analysis reveals the domain was registered on June 12, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with malicious registrations. The domain resolves to the IP address 188.114.97.3, which has been linked to multiple phishing campaigns in recent months. Detection metrics show that 6 of 95 security vendors on VirusTotal have flagged rewards-ssv.network as malicious, while it appears on three independent security blocklists. The SSL certificate, issued by Google Trust Services (WE1), provides a false sense of legitimacy but does not mitigate the underlying threat. Current status indicates the domain remains active and continues to evade takedown efforts. Users are strongly advised to avoid interaction with rewards-ssv.network and any associated links. Network-level blocking of the IP 188.114.97.3 is recommended for enterprise environments. Cryptocurrency holders should verify all reward or airdrop claims through official SSV Network channels and enable hardware-based or multi-factor authentication for wallet access. Monitoring for unauthorized transactions is critical for those who may have previously engaged with the domain.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
8 monitored external feeds No match
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
3 high-confidence technologies identified
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive