solana-wallet[.]io
“Solflare Wallet - The Most Powerful Solana Crypto Wallet”
solana-wallet.io — Non vérifié. Usurpation de l'identité de la marque : Solana; Type d'arnaque : Wallet/seed Phishing. Résumé des preuves: VirusTotal 10/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); PhishDestroy score 88/100. Bureau d’enregistrement: Web Commerce Communica….
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of solana-wallet.io shows a confirmed wallet‑seed phishing operation that targets Solana users. The domain was registered on August 02, 2025 through Web Commerce Communications Limited and resolves to the IPv6 address 2a06:98c1:3121::3, which is announced by AS13335 Cloudflare, Inc. and geolocated to the United States. Both authoritative nameservers, clayton.ns.cloudflare.com and meilani.ns.cloudflare.com, are hosted on Cloudflare infrastructure, indicating the attacker leveraged a reputable CDN to mask the true origin of the site. No TLS certificate was presented, meaning the site operated without HTTPS protection.
The page title observed during crawling reads "Solflare Wallet - The Most Powerful Solana Crypto Wallet," explicitly referencing the Solflare product and the Solana blockchain, which aligns with the reported scam type of wallet/seed phishing. The domain is listed on a single security blocklist and has been flagged by four of ninety‑five VirusTotal scanners, reflecting limited but notable detection across the threat‑intel ecosystem. PhishDestroy has taken the domain offline, and current checks confirm the site is no longer reachable.
While the offline status reduces immediate exposure, the infrastructure artifacts—especially the Cloudflare IP and the lack of SSL—remain reusable for future impersonation campaigns. Defenders should block the IPv6 address and the domain at perimeter filters, monitor for similar page titles or brand keywords, and enforce strict validation of SSL certificates for any Solflare‑related traffic. Continuous observation of the registrar and nameserver changes is advised, as attackers may reactivate the domain or spin up new clones using the same registration details.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif