Analysis as of July 30, 2026 indicates that the domain clickfast-mint4.netlify.app remains active and is classified as a high‑risk crypto drainer. The site is hosted on Netlify and resolves to the IPv4 address 63.176.8.218. Google Safe Browsing has flagged the domain for social engineering, and VirusTotal reports that 19 of 91 security vendors have identified it as malicious. Independent blocklists confirm its presence on three separate blocklists, and the domain is explicitly blocked by the PhishDestroy, MetaMask, and SEAL filtering services.
The registrar information shows that the domain was provisioned through Netlify, and the nameserver query returned NS_NOT_FOUND, suggesting that standard DNS delegation records are unavailable or have been intentionally obscured. No additional metadata such as SSL certificate details, HTTP response codes, or page title have been disclosed, leaving the content of the site unverified. The current evidence points to an infrastructure that is being leveraged to solicit cryptocurrency transfers, likely through deceptive prompts or contract interactions, which aligns with the “crypto drainer” designation.
Defenders should prioritize blocking the domain at network perimeter and endpoint layers, incorporate the IP address 63.176.8.218 into deny lists, and ensure that any browser or wallet extensions that query Google Safe Browsing or VirusTotal are kept up‑to‑date to capture the reported detections. Continuous monitoring of the domain’s DNS resolution and blocklist status is advisable, as changes in hosting or name‑server configuration could alter its attack surface. Organizations that use MetaMask or similar wallet extensions should verify that their security policies include the listed blocklist providers to mitigate exposure.