layer2-lava[.]pages[.]dev
“Multi-chain RPC that just works”
Resumo das evidências
PhishDestroy identifies layer2-lava.pages.dev as an active crypto drainer impersonating a Layer2 bridging service. The domain leverages a Cloudflare Pages subdomain to host a fraudulent interface designed to siphon cryptocurrency assets from unsuspecting users. This drainer kit is engineered to deceive visitors into connecting their wallets under the guise of bridging tokens across Layer2 networks, with malicious scripts silently exfiltrating funds upon authorization. This domain exhibits several suspicious technical indicators. According to VirusTotal, it currently shows 1/95 detections despite its malicious activity, indicating delayed recognition by threat intelligence feeds. The domain was registered through Cloudflare, Inc. and resolves to IP 172.66.47.201. The SSL certificate is issued by Google Trust Services, which is commonly exploited by threat actors to lend false legitimacy to fraudulent sites. As of the investigation seed d97b4d, this domain remains unlisted on major blocklists, though its low VT score suggests imminent detection. The current status of layer2-lava.pages.dev is active, with PhishDestroy continuing to monitor its infrastructure. No takedown action has been initiated as of this report, leaving users at risk of further exploitation. Users are strongly advised to verify any Layer2 bridging services against PhishDestroy’s database before interacting with wallet connections. Until the domain is flagged by additional security vendors or taken offline, the risk of exposure to crypto drainer attacks remains critical.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of layer2-lava.pages.dev · checked Apr 2, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo