# scanwallet.pages.dev — SUSPICIOUS > PhishDestroy identifies scanwallet.pages.dev as a live crypto-draining scam. Zero VirusTotal detections as of seed 2ebe09. Check the full report. ## Summary PhishDestroy identifies scanwallet.pages.dev (seed 2ebe09) as an active crypto-drainer phishing site designed to silently steal cryptocurrency from unsuspecting users. This fraudulent page impersonates a legitimate wallet-scanning service, tricking victims into connecting their wallets so attackers can drain funds via malicious transaction signatures. Evidence shows the domain resolves to IP 188.114.97.3 and operates behind a Cloudflare shield, masking its true infrastructure while presenting a Google Trust Services SSL certificate to appear legitimate. Zero VirusTotal engines detected the threat at the time of assessment, illustrating how new crypto-draining pages evade immediate detection despite their malicious intent. This domain was flagged by PhishDestroy due to confirmed crypto-draining functionality and is currently under active investigation. The site is hosted on Cloudflare infrastructure and leverages a valid SSL certificate from Google Trust Services to enhance credibility. Its VirusTotal scan resulted in 0 out of 95 detection engines flagging it, highlighting the evasive nature of emerging crypto-drainers. While no public blocklist entries were identified at this stage, the combination of active deployment, cryptocurrency targeting, and zero initial detections makes it a high-risk vector for wallet compromise. Users who visited scanwallet.pages.dev should immediately disconnect any connected wallets, revoke any unauthorized permissions via their wallet’s security settings, and thoroughly scan their devices for malware. Do not interact with wallet connection prompts unless you can 100% verify the legitimacy of the service. Report any unauthorized transactions to your wallet provider and consider transferring remaining funds to a new, secure wallet. Stay informed by checking updated threat intelligence reports to avoid repeat exposure. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/d811e7eb-6049-4b88-aff0-859b18e6fece - PhishDestroy: https://phishdestroy.io/domain/scanwallet.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/scanwallet.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/scanwallet.pages.dev/ Last updated: 2026-03-28