walletconnectauth[.]com
“Wallet Auth Validator – | Connect Wallet”
Сводка доказательств
Analysis of walletconnectauth.com confirms it as a high-risk crypto scam domain targeting WalletConnect users. The domain was registered on March 23, 2025, through Tucows Domains Inc. and is currently offline. Infrastructure analysis reveals it resolved to an IPv6 address (2a02:4780:2b:1869:0:32c3:fe0c:a) hosted on AS47583 (Hostinger International Limited) in the US. Nameservers point to ns1.dns-parking.com and ns2.dns-parking.com, a pattern consistent with low-cost, disposable phishing infrastructure. The domain appears in 15 AlienVault OTX threat intelligence pulses, indicating prior detection by security researchers.
Sixteen of 95 security vendors on VirusTotal flagged the domain as malicious, though the exact detection categories remain unconfirmed. It is listed on three security blocklists, including PhishDestroy, MetaMask, and SEAL, which suggests targeted blocking by wallet security providers. The page title, 'Wallet Auth Validator – | Connect Wallet,' explicitly references WalletConnect’s authentication flow, reinforcing the brand impersonation. No SSL certificate was present, a red flag for phishing sites handling sensitive credentials.
The domain’s creation date (16 months prior to the report) aligns with long-term scam campaigns rather than opportunistic attacks. Defenders should treat this domain as confirmed malicious infrastructure. Blocklist integration is recommended, particularly for crypto wallet and DeFi platforms. Given its offline status, defenders should monitor for re-registration or DNS changes, as this infrastructure may resurface under a similar naming scheme or hosting provider.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 10.08.2026
8 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Архивные доказательства
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание