The domain web3-eexoduus-wallett.gitbook.io is currently classified as a high-risk crypto drainer threat as of July 28, 2026. Security intelligence shows this domain has been flagged by PhishDestroy, and it appears on at least one reputable security blocklist. Detected as active, the domain continues to operate without mitigation at the time of this report. According to VirusTotal, 12 out of 91 security vendors have marked this domain as malicious, which further solidifies the assessment of an active threat.
The domain resolves to IP address 172.64.147.209 and uses Cloudflare for both registration and nameservers (dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com). The creation date is recorded as March 30, 2014, indicating it may be using aged infrastructure or a repurposed subdomain within the gitbook.io platform. There is no explicit web content, page title, or brand evidence provided to clarify the specific tactics or lures being employed on the site, apart from its categorization as a crypto drainer. The lack of further technical indicators such as SSL certificate details or additional trust scores means some aspects of its operation remain uncertain.
However, the convergence of multiple vendor detections and blocklist inclusion justifies a high-risk classification. Security personnel should ensure this domain is blocked across web gateways, DNS security solutions, and endpoint protection platforms. No direct links to user compromise or transaction logs are present in the observed intelligence, but continued monitoring for associated infrastructure is recommended, given the domain’s active status and risk profile.