web3nodeprotocol[.]app
Forensic brief
PhishDestroy has flagged web3nodeprotocol.app as an active crypto drainer impersonating a Web3 protocol node service. The site is designed to trick cryptocurrency users into connecting wallets under the guise of earning rewards or accessing exclusive features. This domain specifically targets users of decentralized finance (DeFi) platforms by mimicking legitimate blockchain infrastructure tools, a common tactic used by drainer kits to extract private keys or authorize malicious transactions. No known brand impersonation has been confirmed at this time, but the threat vector aligns with generic drainer operations observed in similar campaigns. This domain resolves to IP address 198.251.84.200 and is registered through Sav.com, LLC. The SSL certificate is issued by Let’s Encrypt, a detail often abused by threat actors to appear legitimate. The domain was created on April 13, 2026, indicating it is extremely new and likely spun up for a short-lived campaign. VirusTotal currently shows 0 detections out of 95 scanners, suggesting it remains under the radar of most threat intelligence feeds. Google Safe Browsing (GSB) status is unknown at this stage, and no blocklist counts are publicly available. These technical indicators suggest a low-profile, opportunistic campaign with high potential for evasion. PhishDestroy currently classifies this domain as active with a risk level under investigation. The generic phishing label reflects its use as a crypto drainer, though specific drainer kit signatures have not been confirmed in open sources. The domain’s recent creation and lack of detections indicate a high risk of rapid evolution or expansion. Users are strongly advised to avoid interacting with web3nodeprotocol.app and to verify any similar domains using PhishDestroy’s real-time tool. While the immediate risk is elevated due to the drainer’s targeted nature, the lack of widespread detection increases the likelihood of successful exploitation before remediation. Continuous monitoring and user vigilance are essential to mitigate potential losses.
Threat response pipeline
Cloudflare Radar
VirusTotal
Forensic Evidence Collectionabuse-contact@sav.com with forensic evidence (metadata, screenshots, PDF).Evidence capture
Domain Intelligence
Sav.com, LLC
Technical details
Registrar inaction · RAA §3.18
ICANN RAA §3.18 co-responsibility window expired on day 1; we re-mailed at 24h, 72h and 7d thresholds with a full forensic evidence bundle (HAR + DOM + screenshots + kit hashes). The registrar has not acknowledged. Public escalation is now warranted.
Public blocklist status
Technologies
Technologies · 6 identified
VirusTotal consensus
Aggregated detection across 95 security vendors.
Site performance
Site performance analysis
Google PageSpeed Insights — mobile audit of web3nodeprotocol.app
Evidence & external reports
Were you affected by this site?
Were You Affected?
Report to your local authorities
Email template — registrar abuse
abuse-contact@sav.com
Registrar: Sav.com, LLC Case: PD-PD-20260415-626CAB
Embed this report
About this report
About this report: web3nodeprotocol.app
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal and 3 public blocklists.
The site displays a page titled “Blockchain Lightning Node”.
web3nodeprotocol.app has been flagged by 2 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.