# vote-moonwell.fi — SUSPICIOUS > vote-moonwell.fi identified as a fake voting site. VirusTotal shows 0/95 detections. Check the full report for details and safety steps. ## Summary PhishDestroy identifies vote-moonwell.fi as a **fake voting site actively impersonating Moonwell**, a legitimate decentralized finance (DeFi) protocol. This domain lures users into entering credentials or cryptocurrency details under the guise of participating in an official governance vote. The threat is classified as a **generic phishing** attack, where attackers exploit trust in legitimate platforms to steal sensitive data or assets. The site mimics the appearance of Moonwell's interface to deceive visitors into believing it is authentic, with the primary goal of harvesting wallet addresses, private keys, or transaction approvals. This domain exhibits several red flags confirmed by forensic analysis. It was registered through Key-Systems GmbH on March 13, 2026, a recent creation that bypasses traditional trust signals like domain age. The site operates with a valid Let's Encrypt SSL certificate, leveraging HTTPS to appear legitimate, but this offers no protection against phishing. VirusTotal currently flags the domain with 0 detections out of 95 security scanners, indicating it has yet to be widely recognized as malicious. While the absence of detections does not confirm safety, it highlights the need for immediate caution. The domain resolves to IP 188.114.96.3, a hosting address associated with multiple suspicious activities. Despite these indicators, the absence of blocklist entries suggests this campaign may be newly deployed or targeted at a specific user base. If you visited vote-moonwell.fi, assume your credentials or cryptocurrency assets are at risk. Do not connect your wallet or enter any private information on this site. Revoke any unauthorized permissions granted to the domain via your wallet's connection settings (e.g., MetaMask, WalletConnect). If you entered sensitive data, immediately transfer remaining assets to a secure wallet and enable two-factor authentication. Report the incident to Moonwell's official support channels and consider scanning your device for malware. Avoid interacting with this domain further, as it remains active and poses an ongoing threat to unsuspecting users. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-13 00:00:00 - Registrar: Key-Systems GmbH - IP: 188.114.96.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/0a9b312c-41fe-49fb-ad7b-c2ad7dca0fea - PhishDestroy: https://phishdestroy.io/domain/vote-moonwell.fi/ - LLM endpoint: https://phishdestroy.io/domain/vote-moonwell.fi/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/vote-moonwell.fi/ Last updated: 2026-03-24