MALICIOUS — CRITICAL
tronlend[.]fi
The domain tronlend.fi is a confirmed phishing site engaged in brand impersonation targeting users of the cryptocurrency exchange bitget.
- VirusTotal
- 2/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilità
- Ultimo attivo conosciuto · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
tronlend.fi — Ultimo attivo conosciuto (HTTP 200). Simulazione del marchio: Bitget; Tipo di truffa: Wallet/seed Phishing. Riepilogo delle prove: VirusTotal 2/91 (CRDF, Gridinsoft); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 80/100. Registrar: Key-Systems.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
The domain tronlend.fi is a confirmed phishing site engaged in brand impersonation targeting users of the cryptocurrency exchange bitget. It presents itself as a decentralized lending platform on the TRON network, using the page title 'TronLend DAO • Decentralized Lending on TRON', but its primary threat involves wallet connection phishing designed to steal cryptocurrency credentials. As of the latest verification, tronlend.fi has been taken offline, though prior activity classified it as an elevated-risk scam.
Technical indicators confirm the malicious nature of tronlend.fi. The domain is flagged by 1 of 95 VirusTotal security vendors, including SOCRadar, and appears on 3 security blocklists: PhishDestroy, MetaMask, and SEAL. It was registered through Key-Systems GmbH on February 21, 2026, and resolves to the IP address 188.114.97.3, hosted by Cloudflare in the United States. The SSL certificate is issued by Google Trust Services / WE1, and detected technologies include Unpkg, jsDelivr, Cloudflare, Axios, and HTTP/3. Gridinsoft assigns the domain a trust score of 0 out of 100, reinforcing its classification as a phishing threat.
Users who interacted with tronlend.fi should immediately revoke any token approvals granted to the site and transfer remaining funds to a new, secure wallet. If credentials were entered, change passwords on the legitimate bitget platform and enable two-factor authentication. Report the phishing domain to relevant authorities, including the registrar Key-Systems GmbH, and submit the URL to platforms like Google Safe Browsing, PhishTank, or MetaMask’s threat repository to aid in broader mitigation efforts.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 5 identified
JSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.
www.jsdelivr.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of tronlend.fi · checked Apr 30, 2026
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.