# tornadomix.link — SUSPICIOUS > PhishDestroy flags tornadomix.link as a crypto drainer with 0/95 VirusTotal detections, posing high risk to digital asset holders. Take immediate evasive action. ## Summary PhishDestroy identifies tornadomix.link as a live crypto drainer domain currently under investigation for active credential and wallet theft operations. This domain was flagged by PhishDestroy after security engines recorded 0 detections on VirusTotal out of 95 scanners, indicating it remains undetected by standard antivirus tools. The domain was created on March 23, 2026, and is registered through Key-Systems, LLC, resolving to IP address 188.114.97.3. Its SSL certificate was issued by Let's Encrypt, a common tactic used to appear legitimate and secure to visitors. If you visited tornadomix.link, do not enter any wallet addresses, seed phrases, private keys, or login credentials. Disconnect from the site immediately and revoke any permissions granted through wallet connection dialogs. Scan your device with updated antivirus software and consider rotating all cryptocurrency wallet credentials. Enable multi-factor authentication on all exchange and wallet accounts and monitor for unauthorized transactions. Report the domain to your cybersecurity team or file a report with PhishDestroy using seed a3d508 for further analysis and takedown support. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-23 10:11:30 - Registrar: Key-Systems, LLC - IP: 188.114.97.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/4f90c5e4-9f02-4929-a811-421939ee845d - PhishDestroy: https://phishdestroy.io/domain/tornadomix.link/ - LLM endpoint: https://phishdestroy.io/domain/tornadomix.link/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/tornadomix.link/ Last updated: 2026-03-31