This report examines imtoken-wallet.net, a domain currently flagged as a crypto drainer and under active investigation as of July 31, 2026. The domain was registered on July 28, 2026, through GoDaddy.com, LLC, making it only three days old at the time of this assessment. Its registrant details are obscured by GoDaddy's default privacy setup, and the domain uses nameservers ns43.domaincontrol.com and ns44.domaincontrol.com, which are standard GoDaddy infrastructure. The domain resolves to IP address 198.46.189.10, a hosting location that has not been associated with any specific ASN or country in the available intelligence, though its rapid deployment and infrastructure choices are consistent with a disposable phishing operation.
Threat intelligence sources show that imtoken-wallet.net is listed on two security blocklists: PhishDestroy and SEAL. These independent listings indicate that security researchers have already identified this domain as malicious, likely due to its association with cryptocurrency wallet credential theft or transaction-draining scripts. VirusTotal reports that 91 vendors have scanned the domain, with zero currently flagging it. This absence of detections is not proof of safety; many newly registered phishing domains evade automated scanners initially, and the domain's blocklist presence carries more weight than the VirusTotal result. Google Safe Browsing data was not provided in the available intelligence, and no OTX (AlienVault Open Threat Exchange) pulse data was supplied, so the domain's standing on those platforms remains unverified.
The domain name itself, imtoken-wallet.net, strongly suggests an attempt to impersonate the imToken cryptocurrency wallet service. However, the available evidence does not include a confirmed page title, brand target, or kit analysis, so the exact content served on the domain has not been verified.