rugmeput[.]top
This domain rugmeput.top is flagged as a generic phishing threat with an elevated risk level and remains active as of August 03, 2026. Analysis from multiple security sources indicates that the domain is currently listed on three distinct blocklists, which suggests it has been identified as malicious by independent threat intelligence feeds. VirusTotal data shows that 2 out of 91 security vendors flag this domain as malicious, indicating a moderate but notable detection rate across the industry. The domain is specifically blocked by PhishDestroy, MetaMask, and SEAL, with the inclusion of MetaMask implying a potential association with cryptocurrency-related phishing schemes, though this is not definitively confirmed by the available data.
The exact content hosted on the domain has not been analysed, and the page title is not provided in the current intelligence, so the precise nature of the phishing lure remains uncertain. Infrastructure details such as registrar, hosting provider, IP address, and SSL certificate information are not available in the current records, limiting the ability to attribute the domain to a specific actor or hosting environment. There is no evidence from Google Safe Browsing or OTX present in the available intelligence, and no trust score or HTTP status data is supplied. Defenders should treat this domain as a live threat and proactively block access at the DNS, email gateway, and network levels to prevent users from visiting it.
Organisations that rely on MetaMask or similar cryptocurrency wallets should increase user awareness, as the blocking by MetaMask suggests a possible focus on crypto users. Security teams are advised to monitor for any emails, messages, or web links referencing rugmeput.top and to quarantine such communications. Given the active status and elevated risk, immediate action is recommended rather than waiting for additional detections.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
Threat Intel Cross-Reference · source references
VirusTotal Analysis
Evidence & External Reports
“Theres a website called https://rugmeput.top/ that is a wallet drainer whenever you connect your wallet. I just want this to be known before people loose alot of money. They change domains very frequently but DUwvqkGNLKqy42UhmhJ2V2G4optDpMka4oKHUYhDxHd is one of the main wallets they use. https://solscan.io/tx/5hzdXqpmC14PYmmM7iBspEsVrr7UMjxHfZ8fM6i5Xfef2s4E58Wn9vch6p7F8yB8GoUHaqk62aKarYCNaBdg82Sz this is the solscan of where i was drained. (I'm poor so it was only .8 sol but i dont want someone”
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive