# trxstaking.pages.dev — SUSPICIOUS > trxstaking.pages.dev surfaces as a classic crypto-staking phishing page hosted behind Cloudflare. VT shows 0/95 detections so far. Check the full report. ## Summary PhishDestroy identifies trxstaking.pages.dev as a live classic crypto-staking phishing lure aimed at TRON (TRX) holders. The site masquerades as an official staking portal, prompting users to connect their wallets and approve malicious token approvals that drain assets directly. Domain age is still under review, but hosting is pinned to Cloudflare’s edge at 172.66.47.77 via Google Trust Services SSL, giving it an initial veneer of legitimacy while actively harvesting credentials and private keys. VirusTotal currently flags the domain with 0 out of 95 engines detecting the threat, and no public blocklist integrations have flagged it yet. Registrant details remain obscured by Cloudflare’s privacy service, aligning with common red-flag behavior in phishing operations. The IP infrastructure sits behind Cloudflare’s proxy, complicating takedown efforts and allowing operators to pivot quickly to new hostnames. If you accessed trxstaking.pages.dev, disconnect your wallet immediately using your wallet’s disconnect function rather than just closing the browser. Revoke any token approvals via reputable revoke sites, reset browser extensions, and run a full antivirus scan. Report the domain to your wallet provider and consider rotating all private keys that may have been exposed. Forward any transaction hashes or wallet addresses linked to this domain to your security team for further analysis. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: Cloudflare, Inc. - IP: 172.66.47.77 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/36c07da3-d17d-4b9f-bf27-9e873ae06717 - PhishDestroy: https://phishdestroy.io/domain/trxstaking.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/trxstaking.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/trxstaking.pages.dev/ Last updated: 2026-03-27