phantom-my[.]at
Forensic brief
Read full brief
PhishDestroy identifies phantom-my.at as an active Solana crypto drainer impersonating the Phantom wallet. This domain was flagged by 13/13 VirusTotal security vendors, indicating widespread suspicion of malicious activity. Registered through Hosting Concepts B.V. via Registrar.eu, the domain resolves to IP 45.59.122.25 and utilizes a Let's Encrypt SSL certificate to appear legitimate.
The drainer kit is specifically designed to target Solana wallet users, posing a high risk of cryptocurrency theft. The domain phantom-my.at leverages brand impersonation to deceive users into entering their wallet credentials or connecting their wallets to malicious smart contracts. Phantom wallet users are specifically targeted, as the scam domain mimics the official Phantom branding to lend credibility.
The Solana drainer kit is equipped to siphon funds from connected wallets without requiring explicit transaction approvals, making it a particularly dangerous threat. Evidence of its malicious nature is corroborated by its presence on multiple blocklists and the high detection rate on VirusTotal. Users who have visited phantom-my.at should immediately disconnect their wallets from the site and revoke any connected permissions via their wallet's security settings.
Transferring any remaining funds to a cold wallet or a newly created one is strongly advised. Scanning devices for malware using reputable antivirus software is also recommended, as crypto drainers often bundle additional payloads. Report the domain to PhishDestroy and your wallet provider to help prevent further victimization.
Threat response pipeline
Cloudflare Radar
VirusTotal
Forensic Evidence Collectionabuse-reports@cloudzy.com with forensic evidence (metadata, screenshots, PDF).Evidence capture
Domain Intelligence
Hosting concepts B.V. / Registrar.eu ( https://nic.at/registrar/648 )
Technical details
Public blocklist status
Technologies
Technologies · 1 identified
VirusTotal consensus
Aggregated detection across 13 security vendors.
Site performance
Site performance analysis
Google PageSpeed Insights — mobile audit of phantom-my.at
Evidence & external reports
Were you affected by this site?
Were You Affected?
Recommendations & Advice for Victims
- Do not pay anything else. Recovery agents demanding upfront fees are a second-stage scam.
- Disconnect compromised wallets. Move remaining funds to a fresh seed phrase generated offline.
- Preserve evidence. Screenshot transactions, save URLs, archive emails — chain-of-custody matters for prosecution.
- Report to authorities (see section 15 below) — even small reports help build case patterns.
- Notify your bank/exchange. Some chargebacks may still be possible within 24-72h.
Report to your local authorities
Email template — registrar abuse
abuse-reports@cloudzy.com
Registrar: Hosting concepts B.V. / Registrar.eu ( https://nic.at/registrar/648 ) Case: PD-20260517-BF78F3
Embed this report
About this report
About this report: phantom-my.at
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 13 security vendors on VirusTotal and 1 public blocklists.
The site displays a page titled “Site is being set up...”.
phantom-my.at has been flagged by 13 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.