# trustchangewbwers.com — SUSPICIOUS > trustchangewbwers.com is a brand-new crypto drainer with 0/95 VirusTotal detections. Created July 21, 2025, it impersonates a token swap portal—avoid at all. ## Summary PhishDestroy identifies trustchangewbwers.com as a recently activated crypto drainer that tricks visitors into connecting wallets and signing malicious transactions. The site mimics a legitimate token-swap interface, luring users with promises of fast, low-fee exchanges before draining funds directly from connected wallets. Its domain was registered only days ago and already shows signs of live phishing campaigns targeting cryptocurrency holders. This domain was flagged by PhishDestroy with zero detections out of 95 VirusTotal scanners as of July 23, 2025. The site resolves to IP 188.114.97.3 and was registered on July 21, 2025 through Gname.com Pte. Ltd. under a newly issued Google Trust Services SSL certificate, a tactic commonly used to appear legitimate. Despite low detection rates, the domain’s age, registrar, and hosting profile match known crypto-draining infrastructure, placing it under active investigation. If you visited trustchangewbwers.com, immediately disconnect your wallet and revoke any approvals using tools like revoke.cash or your wallet’s built-in allowance manager. Do not interact further with the site. Scan your device with updated antivirus software and consider rotating private keys for wallets that may have been exposed. Report the domain to your wallet provider and relevant fraud databases. Always verify swap sites via official project links and never enter seed phrases or authorize unexpected transactions. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2025-07-21 04:14:19 - Registrar: Gname.com Pte. Ltd. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/ebcecde3-24e4-426c-a225-020ffb49e9d3 - PhishDestroy: https://phishdestroy.io/domain/trustchangewbwers.com/ - LLM endpoint: https://phishdestroy.io/domain/trustchangewbwers.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/trustchangewbwers.com/ Last updated: 2026-03-26