Analysis of sweetpoint.best confirms its classification as an active phishing domain with high-risk indicators targeting cryptocurrency users. Registered on July 13, 2026, through NAMECHEAP INC, the domain currently resolves to IP address 172.67.206.67, hosted on Cloudflare infrastructure as evidenced by its nameservers (chad.ns.cloudflare.com and eloise.ns.cloudflare.com). Security vendors have begun flagging the domain, with 3 out of 91 engines on VirusTotal detecting malicious activity. It appears on three security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, suggesting a focus on cryptocurrency-related fraud.
The domain's recent creation, combined with its presence on multiple blocklists within weeks of registration, aligns with typical phishing campaign timelines. While the exact content of the site remains unanalyzed, the inclusion in MetaMask's blocklist indicates a likely attempt to harvest wallet credentials or deploy crypto-draining scripts. Infrastructure analysis reveals no legitimate business association, and the use of Cloudflare nameservers is consistent with threat actors seeking to obscure hosting origins. Defenders should treat this domain as confirmed malicious.
Network-level blocking is recommended for the domain and its resolving IP. Security teams should monitor for related domains registered through the same registrar or utilizing identical nameserver patterns, as these may indicate follow-on campaigns. Given the domain's active status as of July 31, 2026, and its rapid detection by specialized crypto-security tools, continued vigilance is warranted for potential credential theft or wallet compromise attempts.