# t81293-robinhood.com — SUSPICIOUS > Security alert: t81293-robinhood.com impersonates Robinhood with a fake login page designed to steal crypto. Verify instantly with PhishDestroy. ## Summary PhishDestroy identifies t81293-robinhood.com as an active crypto drainer domain impersonating the Robinhood trading platform. The site employs a spoofed login interface to harvest credentials and wallet private keys, redirecting stolen funds to attacker-controlled addresses. This campaign targets users seeking to log in to Robinhood services, leveraging the brand's credibility to bypass security awareness. This domain was flagged with a VirusTotal detection ratio of 0/95 engines as of the latest scan, indicating it remains largely undetected by antivirus vendors. It was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to the IP address 104.21.50.156. The domain was created on March 20, 2026, and is secured with a valid SSL certificate issued by Google Trust Services, which may enhance its perceived legitimacy among potential victims. At the time of reporting, this site has not been listed on major blocklists such as Google Safe Browsing or PhishTank. The domain remains active and under investigation with a risk level categorized as under_investigation. Current remediation efforts include ongoing monitoring by PhishDestroy and submission to threat intelligence feeds. However, due to its low detection rate and recent creation, users are strongly advised to avoid accessing this domain and to verify any Robinhood-related links using PhishDestroy before entering login credentials or cryptocurrency wallet information. The remaining risk is considered high for uninformed users who may interact with this malicious page, particularly those unfamiliar with verifying domain authenticity prior to data entry. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: Robinhood ## Domain Intelligence - Registered: 2026-03-20 16:39:51 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 104.21.50.156 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/35e0c75f-77d1-4e58-9880-46ee3340b651 - PhishDestroy: https://phishdestroy.io/domain/t81293-robinhood.com/ - LLM endpoint: https://phishdestroy.io/domain/t81293-robinhood.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/t81293-robinhood.com/ Last updated: 2026-03-23