# trustswallet.ltd — SUSPICIOUS > Trustswallet.ltd operates as a crypto drainer. VirusTotal shows 0/95 detections. Check the full report. ## Summary PhishDestroy identifies trustswallet.ltd as an active crypto drainer domain designed to steal cryptocurrency assets under seed ed09a8. This fraudulent site mimics a legitimate wallet service to trick users into connecting wallets and authorizing malicious transactions. Threat actors harvest private keys and seed phrases, enabling direct fund extraction. The domain has not yet been flagged by most security engines (0/95 on VirusTotal), indicating low detection rates despite clear malicious intent. This domain was flagged by PhishDestroy on March 21, 2026, only days after creation, suggesting opportunistic deployment. It is registered through GoDaddy.com, LLC and resolves to IP 76.223.105.230 with an SSL certificate issued by GoDaddy.com, Inc. The combination of fresh registration, low detection, and cryptocurrency targeting elevates risk. While currently undetected by most engines, its active status and drainer functionality pose imminent threat to users engaging with wallet-related services. If you visited trustswallet.ltd or entered any credentials or wallet connections, immediately revoke connected permissions using your wallet’s official interface (e.g., MetaMask, Trust Wallet). Do not interact further with this domain or any links from unsolicited messages. Report the domain to your antivirus provider and monitor wallet activity for unauthorized transactions. Disconnect affected wallets from all dApps and reset exposure. Share this advisory to prevent others from falling victim to this drainer campaign under seed ed09a8. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-21 21:08:22 - Registrar: GoDaddy.com, LLC - IP: 76.223.105.230 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/9d07ff0f-17d7-42f1-bb21-7b469422e56f - PhishDestroy: https://phishdestroy.io/domain/trustswallet.ltd/ - LLM endpoint: https://phishdestroy.io/domain/trustswallet.ltd/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/trustswallet.ltd/ Last updated: 2026-03-23