megadrop-bouncebit[.]pages[.]dev
“Points Paradise”
Resumo das evidências
PhishDestroy identifies megadrop-bouncebit.pages.dev as an active cryptocurrency-draining page posing an elevated risk to visitors with digital-asset wallets.
This domain masquerades as a legitimate landing page but is engineered to intercept and drain funds from connected Web3 wallets. When a victim approves a fraudulent transaction signature, the site covertly transfers tokens to attacker-controlled addresses, leaving the wallet holder with irreversible losses. The underlying payload is delivered via obfuscated JavaScript served from 188.114.97.3, a Cloudflare-peered IP address known for hosting crypto-drainer scripts. At least one security vendor (ScamSniffer) and the Enkrypt browser extension have independently marked the domain as malicious, yet the site remains accessible and shows signs of continued updates.
This page was registered through Cloudflare, Inc. on an unknown date earlier in 2024 and immediately attracted scrutiny; VirusTotal’s collective scan engine now shows 1 out of 95 participating security products detecting the threat, a low but telling count that signals both low prevalence and emerging evasion techniques. The presence of a Google Trust Services SSL certificate gives a misleading veneer of legitimacy, but the certificate only confirms domain ownership, not site safety. Anyone who visited the page should immediately revoke any wallet-connect approvals via the blockchain explorer or wallet’s built-in revocation tool, transfer remaining assets to a clean wallet, and run a malware scan on all connected devices. If funds are drained, file a police report and submit the transaction IDs to the blockchain analytics platform used by your wallet; this evidence may aid in fund recovery or law-enforcement tracing.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 13/08/2026
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo