# succesadevsolanasx.pages.dev — MALICIOUS — Crypto Drainer (Solana Drainer) > succesadevsolanasx.pages.dev is a live Solana crypto drainer impersonating developers. Blocked by ScamSniffer with 3/95 VirusTotal detections. ## Summary succesadevsolanasx.pages.dev is a high-risk Solana cryptocurrency drainer domain currently active and propagating fraudulent schemes targeting Solana ecosystem users. PhishDestroy’s forensic analysis confirms this domain operates a Solana drainer kit designed to siphon funds from unsuspecting wallets under the guise of developer tools or legitimate services. The threat actor leverages deceptive branding and social engineering tactics, often mimicking official developer portals or project websites to trick users into connecting their wallets or entering seed phrases. This domain specifically hosts a drainer kit that automatically initiates unauthorized token transfers upon wallet interaction, exploiting user trust and blockchain transaction approvals. The operational infrastructure is built to appear legitimate through the use of Cloudflare’s infrastructure and a valid SSL certificate issued by Google Trust Services, increasing the appearance of credibility. PhishDestroy assesses this domain as a high-risk threat due to its active drainer functionality and confirmed malicious intent within the Solana ecosystem. Technical indicators corroborate the malicious nature of this domain. PhishDestroy’s analysis reveals this domain resolves to IP address 172.66.44.187, a Cloudflare-hosted endpoint used for malicious redirection. The domain was registered through Cloudflare, Inc., utilizing their privacy-protecting services to obscure ownership details. As of this assessment, the domain is flagged by ScamSniffer, a leading blockchain security platform, and appears on one active security blocklist. VirusTotal analysis reports a detection ratio of 3 out of 95 security vendors identifying this domain as malicious, indicating limited but present recognition by the security community. Despite the low VT coverage, the presence of a Solana-specific drainer kit and active targeting within the Solana ecosystem significantly elevates the risk profile. The domain leverages a valid SSL certificate from Google Trust Services, which may further deceive users into believing the site is trustworthy. These technical markers align with known patterns of sophisticated crypto drainer operations that prioritize evasion and operational persistence. As of the latest assessment, this domain remains active and poses an ongoing threat to Solana users. PhishDestroy has flagged this domain with unique seed identifier a227a1 and continues to monitor its behavior for updates to infrastructure or tactics. Users are strongly advised against interacting with this domain or any associated URLs. Immediate actions include avoiding wallet connections, refraining from entering credentials, and verifying any suspicious domains through PhishDestroy’s verification system. While the domain is currently blocked by ScamSniffer and flagged on one blocklist, the threat remains dynamic, with potential for changes in hosting, SSL certificates, or drainer functionality. The residual risk remains high due to the active drainer kit and the likelihood of continued targeting of Solana ecosystem participants. PhishDestroy recommends exercising extreme caution when engaging with developer or project-related websites and always validating URLs through trusted security platforms before any wallet interaction. ## Threat Details - Verdict: MALICIOUS — Crypto Drainer (Solana Drainer) - Site status: unknown (HTTP ?) - Drainer type: Solana Drainer ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.44.187 ## Detection Status - VirusTotal: 3 vendors flagged - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["ScamSniffer"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/41e9a0a5-0b3d-4bb4-90c0-d6c0ad398e10 - PhishDestroy: https://phishdestroy.io/domain/succesadevsolanasx.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/succesadevsolanasx.pages.dev/llm.txt ## If You Visited This Site 1. Revoke all token approvals immediately (revoke.cash / unrekt.net) 2. Move remaining funds to a new wallet 3. Do not interact with any transactions from this site 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/succesadevsolanasx.pages.dev/ Last updated: 2026-03-22