atomic-wallet[.]to
“Home Page”
Résumé des preuves
PhishDestroy identifies atomic-wallet.to as a brand impersonation threat specifically targeting users of Atomic Wallet, a legitimate cryptocurrency wallet. This domain is designed to trick visitors into believing they are on the official Atomic Wallet website, with the ultimate goal of stealing sensitive information such as login credentials, private keys, or seed phrases. The threat type is a crypto drainer, meaning that once a user enters their wallet details, the attackers can remotely access and drain funds from the victim's cryptocurrency wallet. The domain's title, "Home Page," is deliberately generic to avoid raising suspicion, but its sole purpose is to facilitate credential theft and asset theft.
Technical evidence strongly supports the malicious nature of this domain. VirusTotal reports that 14 out of 95 security vendors flag atomic-wallet.to as malicious, a significant detection rate that underscores the widespread recognition of its threat. The domain was registered on May 6, 2025, through the Government of Kingdom of Tonga, a registrar often associated with low scrutiny and abuse. It appears on at least one security blocklist and has been identified in three threat intelligence pulses on AlienVault OTX. The site lacks an SSL certificate, meaning any data transmitted is unencrypted and easily intercepted. The domain resolves to IP address 2606:4700:3031::6815:4918, which is associated with Cloudflare, a service that can obscure the true hosting location. As of the latest check, the domain has been taken offline, but similar sites may reappear under different domains.
If a user has visited atomic-wallet.to or entered any information, they should immediately consider their wallet compromised. The first step is to transfer all funds from the affected wallet to a new, secure wallet that has never been used on any suspicious site. Users should also change passwords for any associated accounts and enable two-factor authentication wherever possible. Running a full antivirus scan on the device is recommended, as the site may have attempted to deliver malware. Finally, users should report the domain to relevant authorities and monitor their accounts for any unauthorized activity. PhishDestroy advises always verifying URLs before entering sensitive information and using official channels to access cryptocurrency services.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif