# rocketonsol.fun — SUSPICIOUS > rocketonsol.fun is a crypto-drainer site impersonating Rocket Pool; it has 0/95 VirusTotal detections and was registered April 03, 2026. ## Summary PhishDestroy identifies rocketonsol.fun as an active crypto-drainer page posing as the Rocket Pool brand. The site masquerades as a legitimate airdrop portal, using the title “ROCKET | AirDrop” and a Let’s Encrypt SSL certificate to appear trustworthy. Visitors are prompted to connect a wallet under the false promise of receiving Rocket Pool tokens, at which point the drainer would silently transfer all supported assets to attacker-controlled addresses. This is not a generic phishing page; it is specifically designed to empty cryptocurrency wallets in seconds once wallet permissions are granted. This domain was flagged on April 03, 2026, and registered through Spaceship, Inc., resolving to 104.21.34.128. VirusTotal currently shows 0 detections out of 95 engines, meaning most antivirus and browser scanners have not yet blacklisted the page. The unusually short domain age combined with zero detections suggests the campaign is still in its early propagation phase, targeting users via social media, Discord, and Telegram channels where Rocket Pool is frequently discussed. If you visited rocketonsol.fun you should immediately revoke any wallet connections you granted and move remaining assets to a clean wallet. Use reputable tools such as WalletConnect’s revoke.cash or Etherscan’s token approval tracker to remove permissions. Scan your device with up-to-date antivirus software and consider rotating all private keys or seed phrases used on the suspected page. Report the domain to PhishDestroy and your wallet provider to help raise community awareness and speed up detection updates. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: Rocket Pool - Page title: ROCKET | AirDrop ## Domain Intelligence - Registered: 2026-04-03 18:22:57 - Registrar: Spaceship, Inc. - IP: 104.21.34.128 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/rocketonsol.fun - PhishDestroy: https://phishdestroy.io/domain/rocketonsol.fun/ - LLM endpoint: https://phishdestroy.io/domain/rocketonsol.fun/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/rocketonsol.fun/ Last updated: 2026-04-06