# rewards-wen.network — MALICIOUS — Crypto Drainer (Solana Drainer) > rewards-wen.network linked to Solana crypto drainer kit. Domain offline but flagged on security blocklists. Stay cautious and avoid suspicious links. ## Summary PhishDestroy identifies rewards-wen.network as a low-risk crypto drainer domain, primarily targeting Solana cryptocurrency holders. The site promoted deceptive airdrops under the guise of "Wen | Airdrop" to trick users into compromising their wallet credentials. Although the domain is currently offline, its previous activity involved harvesting private keys and draining victims' crypto assets through malicious scripts. The domain was registered through Cloudflare, Inc., resolving to the IP 172.67.202.27, and appeared on three separate security blocklists. VirusTotal analysis shows 2 out of 95 security vendors flagged this domain, reflecting a consensus on its malicious intent. The threat leveraged a known Solana drainer kit, a toolkit designed to automate asset theft from Solana wallets by exploiting user trust in fake airdrop offers. Users should avoid interacting with any links or prompts from rewards-wen.network and remain vigilant against similar phishing attempts offering cryptocurrency rewards. It is crucial to use official wallet provider sources and authenticate URLs carefully. If anyone suspects their wallet has been compromised, they should immediately move assets to a new wallet and update security measures such as seed phrases and private keys. ## Threat Details - Verdict: MALICIOUS — Crypto Drainer (Solana Drainer) - Site status: dead (HTTP 403) - Drainer type: Solana Drainer - Scam type: Airdrop Scam - Kit: Airdrop Scam - Page title: Wen | Airdrop ## Domain Intelligence - Registrar: Cloudflare, Inc. - Country: US - IP: 172.67.202.27 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: lauryn.ns.cloudflare.com mark.ns.cloudflare.com - SSL Issuer: none ## Detection Status - VirusTotal: 2 vendors flagged Vendors: ["Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "MetaMask"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019b276a-99ed-73fa-8b33-c9e1ac04b423.png - Cloudflare Radar: https://radar.cloudflare.com/scan/f889b64f-7970-40c4-a09d-7dc2332cd2c1 - PhishDestroy: https://phishdestroy.io/domain/rewards-wen.network/ - LLM endpoint: https://phishdestroy.io/domain/rewards-wen.network/llm.txt ## If You Visited This Site 1. Revoke all token approvals immediately (revoke.cash / unrekt.net) 2. Move remaining funds to a new wallet 3. Do not interact with any transactions from this site 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/rewards-wen.network/ Last updated: 2026-03-19