eigenwallet[.]io
“EigenWallet – Self-Custody Wallet for Monero & Bitcoin | Cross-Platform”
Resumo das evidências
Analysis of eigenwallet.io indicates a wallet/seed phishing campaign that impersonates the Across brand. The domain was registered through NameSilo, LLC on November 13, 2025 and is hosted on a virtual server in Ukraine (AS30860 Virtual Systems LLC) at IP address 152.89.61.96. DNS resolution points to nameservers ns13.v-sys.org and ns14.v-sys.org, which are commonly observed in malicious infrastructure. No TLS certificate was presented, meaning the site was served over plain HTTP, a typical characteristic of low‑cost phishing deployments. The page title returned by the server reads "EigenWallet – Self‑Custody Wallet for Monero & Bitcoin | Cross‑Platform," but the content has not been publicly examined, leaving the exact visual mimicry unknown.
The domain appears on a single security blocklist and is currently listed as blocked by PhishDestroy, confirming that at least one anti‑phishing provider has taken action against it. VirusTotal scans show that six of ninety‑five security vendors flagged the domain, providing additional corroboration of malicious intent. Gridinsoft’s trust score of 0 out of 100 further emphasizes the lack of legitimacy. The site’s status is recorded as offline, suggesting the operators have removed the payload or are rotating infrastructure.
However, the registration date, hosting details, and detection history remain observable, allowing defenders to attribute future activity to the same actor if similar infrastructure resurfaces. Uncertainties include the precise phishing workflow, the presence of any credential‑stealing forms, and whether the domain ever served malicious binaries. Defenders should continue to monitor the IP address 152.89.61.96 and associated nameservers for re‑use, enforce blocklist updates in web filtering solutions, and ensure that any endpoints that may have accessed the site before takedown are scanned for compromised wallet seeds or related artifacts.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo