atomic-wallet[.]to
“Home Page”
Сводка доказательств
PhishDestroy identifies atomic-wallet.to as a brand impersonation threat specifically targeting users of Atomic Wallet, a legitimate cryptocurrency wallet. This domain is designed to trick visitors into believing they are on the official Atomic Wallet website, with the ultimate goal of stealing sensitive information such as login credentials, private keys, or seed phrases. The threat type is a crypto drainer, meaning that once a user enters their wallet details, the attackers can remotely access and drain funds from the victim's cryptocurrency wallet. The domain's title, "Home Page," is deliberately generic to avoid raising suspicion, but its sole purpose is to facilitate credential theft and asset theft.
Technical evidence strongly supports the malicious nature of this domain. VirusTotal reports that 14 out of 95 security vendors flag atomic-wallet.to as malicious, a significant detection rate that underscores the widespread recognition of its threat. The domain was registered on May 6, 2025, through the Government of Kingdom of Tonga, a registrar often associated with low scrutiny and abuse. It appears on at least one security blocklist and has been identified in three threat intelligence pulses on AlienVault OTX. The site lacks an SSL certificate, meaning any data transmitted is unencrypted and easily intercepted. The domain resolves to IP address 2606:4700:3031::6815:4918, which is associated with Cloudflare, a service that can obscure the true hosting location. As of the latest check, the domain has been taken offline, but similar sites may reappear under different domains.
If a user has visited atomic-wallet.to or entered any information, they should immediately consider their wallet compromised. The first step is to transfer all funds from the affected wallet to a new, secure wallet that has never been used on any suspicious site. Users should also change passwords for any associated accounts and enable two-factor authentication wherever possible. Running a full antivirus scan on the device is recommended, as the site may have attempted to deliver malware. Finally, users should report the domain to relevant authorities and monitor their accounts for any unauthorized activity. PhishDestroy advises always verifying URLs before entering sensitive information and using official channels to access cryptocurrency services.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание