# trustwallletsafe.pages.dev — MALICIOUS > PhishDestroy warns: trustwallletsafe.pages.dev is a crypto drainer phishing site impersonating wallet security portals, flagged by 12 of 95 VirusTotal vendors. ## Summary PhishDestroy identifies trustwallletsafe.pages.dev as an active crypto drainer phishing domain currently leveraging a Cloudflare Pages deployment to deceive users. This malicious infrastructure mimics legitimate wallet security portals to facilitate cryptocurrency theft through fraudulent transaction approvals. The domain remains operational and continues to pose an elevated threat to unsuspecting victims engaging with its fraudulent interface. The domain trustwallletsafe.pages.dev exhibits multiple indicators of compromise across security platforms. Specifically, this malicious resource was flagged by 12 of 95 VirusTotal vendors at the time of analysis, demonstrating significant but not universal detection coverage. The domain is registered through Cloudflare, Inc. and resolves to IP address 188.114.96.3, which hosts the fraudulent content. The SSL certificate, issued by Google Trust Services, provides a false sense of legitimacy to potential victims. While the exact creation date remains unverified in available intelligence feeds, the domain's recent operational status and active phishing campaigns underscore its immediate danger. Users encountering this domain should treat it as a confirmed threat vector requiring immediate action. The infrastructure behind trustwallletsafe.pages.dev demonstrates sophisticated abuse of legitimate cloud services to host malicious content. PhishDestroy recommends blocking this domain at the network perimeter and endpoint levels, implementing user awareness training regarding crypto wallet transaction verification procedures, and deploying browser-based controls to detect and block access to this specific resource. Additionally, affected organizations should scan their networks for potential compromise indicators related to this domain's IP address and SSL certificate fingerprint. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 188.114.96.3 ## Detection Status - VirusTotal: 12 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/2e5529d6-3f67-4ad4-8f8c-0597fd2eeb8c - PhishDestroy: https://phishdestroy.io/domain/trustwallletsafe.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/trustwallletsafe.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/trustwallletsafe.pages.dev/ Last updated: 2026-03-22