# solanarpc.space — MALICIOUS — Crypto Drainer (Solana Drainer) > solanarpc.space is linked to crypto draining attacks. Users should avoid interacting and secure wallets immediately if exposed. ## Summary PhishDestroy identifies solanarpc.space as an active domain involved in crypto drainer operations targeting Solana blockchain users. Crypto drainers are malicious tools designed to covertly steal cryptocurrencies from victims' wallets, leading to direct financial loss. Although this threat currently presents a low risk level, vigilance is critical given the potential impact on digital asset security. The domain solanarpc.space resolves to the IP address 188.114.96.3 and utilizes the Solana Drainer kit, a known malware framework specialized in extracting token holdings from compromised accounts. Registered on March 3, 2026, through NAMECHEAP INC, the domain remains active with limited detection by security vendors, suggesting a stealthy operation aiming to evade widespread detection. This infrastructure setup indicates an ongoing campaign targeting Solana users via phishing or deceptive RPC endpoints. Users are strongly advised to refrain from interacting with solanarpc.space or any unsolicited RPC endpoints claiming to support Solana wallets. Immediate actions include verifying wallet security, revoking suspicious permissions, and transferring funds to a new, secure wallet if any exposure is suspected. Utilizing trusted sources and regularly updating security software can mitigate risks posed by this and similar crypto drainer threats. ## Threat Details - Verdict: MALICIOUS — Crypto Drainer (Solana Drainer) - Site status: alive (HTTP 200) - Drainer type: Solana Drainer - Target brand: Solana - Page title: Solana Space RPC ## Domain Intelligence - Registered: 2026-03-04 13:07:01 - Registrar: NAMECHEAP INC - IP: 188.114.96.3 - Nameservers: summer.ns.cloudflare.com terin.ns.cloudflare.com ## Detection Status - VirusTotal: 2 vendors flagged Vendors: ["Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Live Page Content ### Page Text Solana Space RPC SOLANA SPACE RPC Mission Control // Network Hub Connect Wallet Mainnet Devnet Testnet STATUS Idle LATENCY — SLOT — TPS — RPC ENDPOINT JSON-RPC for reads, writes & simulation H Helius Popular https://mainnet.helius-rpc.com/?api-key=YOUR_KEY Q QuickNode Fast https://solana-mainnet.quiknode.pro/YOUR_KEY A Alchemy https://solana-mainnet.g.alchemy.com/v2/YOUR_KEY T Triton Reliable https://rpc.triton.one/YOUR_KEY P Public RPC Free https://api.mainnet-beta.solana.com Custom Endpoint Apply TPC / TPU FORWARD Transaction submission & leader forwarding D Default TPU mainnet-beta.solana.com:8004 J Jito Block Engine MEV https://mainnet.block-engine.jito.wtf H Helius Staked Staked staked.helius-rpc.com Custom Endpoint Apply SPC / WEBSOCKET Subscriptions, account streams & push data P Public WebSocket Free wss://api.mainnet-beta.solana.com H Helius WebSocket Premium wss://mainnet.helius-rpc.com/?api-key=YOUR_KEY Q QuickNode WS Fast wss://solana-mainnet.quiknode.pro/ws/YOUR_KEY Custom Endpoint Apply Test Connection Save Config Active Config RPC https://mainnet.helius-rpc.com/?api-key=YOUR_KEY TPC mainnet-beta.solana.com:8004 SPC wss://api.mainnet-beta.solana.com Network: Mainnet SOLANA SPACE RPC v1.0 · Mission Control ### External Scripts - https://{domain}/_nuxt/assets/index.js ## Evidence - Screenshot: https://i.ibb.co/XZcqgrhx/b6ebaae3797c.png - Cloudflare Radar: https://radar.cloudflare.com/scan/ad35ee69-f485-4468-85e6-5a5c0e782032 - PhishDestroy: https://phishdestroy.io/domain/solanarpc.space/ ## If You Visited This Site 1. Revoke all token approvals immediately (revoke.cash / unrekt.net) 2. Move remaining funds to a new wallet 3. Do not interact with any transactions from this site 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/solanarpc.space/ Last updated: 2026-03-14