Crypto scam / wallet-drainer
2 of 92 antivirus engines flag this page. Signals match fake investment platforms and wallet drainers. Never connect a wallet, paste a seed phrase, or deposit crypto here.
Is h-cl.top legit or a scam?
Crypto drainer phishing site flagged by security vendors and listed in blocklists, now showing a DNS error page.
These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.
Analysis Summary
MT Intelligence
The domain resolves to a login-themed page titled 'Log In' and was explicitly identified as a crypto drainer by PhishDestroy reports. Two antivirus engines flagged it for phishing and malicious activity. The domain is only 355 days old with privacy protection and no business registration. It shares infrastructure with other known drainer domains such as p-in.cc and at-i.cc. Current DNS failure does not erase the prior malicious use confirmed in the evidence.
Website Preview
Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site.
Visual Screenshot Analysis
We capture a fresh screenshot of the live page and ask a vision model to look for scam visual patterns — fake trust badges, countdown timers, overlay pop-ups, and visual clones of legitimate brands.
No scam visual patterns detected
Screenshot shows a standard browser DNS error page (NXDOMAIN) for h-cl.top; no website content or scam indicators are present.
Web Research Findings
Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for h-cl.top, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.
- Domain h-cl.top registered June 3, 2025 (355 days old) via NameSilo, LLC
- Flagged as active crypto drainer/phishing site by PhishDestroy (3/95 VT detections, listed in MetaMask, SEAL, PhishDestroy blocklists)
- Site title "Log In"; resolves to Cloudflare IP 172.67.176.226
- Associated with similar domains (p-in.cc, at-i.cc, k-fin.cc) sharing drainer kit/infrastructure
- No mentions on Reddit or legitimate review sites; no positive reviews or business records located
- WHOIS and scans confirm recent creation and malicious indicators as of May 2026 reports
- phishdestroy.ioopen
"h-cl.top is a crypto drainer scam flagged by 1/95 VirusTotal vendors. Domain created June 2025 via NameSilo. Site title: "Log In"."
- phishdestroy.ioopen
"PhishDestroy identifies h-cl[.]top as an active crypto drainer domain designed to steal cryptocurrency from unwary users. ... flagged by 3 security vendors ... listed in 3 public blocklists."
PhishDestroy reports identify h-cl.top as a crypto drainer scam flagged by multiple vendors and listed in blocklists including MetaMask and SEAL. The same source links it to related domains using the same drainer kit. No positive reviews or business records were located.
Antivirus Engines
Security Scans
Checked against the major public blocklists used by browsers and security tools — no hits.
Domain & Encryption
Scam-Type Likelihood
2 scam-type patterns detected
0 of 13 categories showed signals
We check every URL against 13 distinct scam categories so the verdict tells you not just how risky the page is, but what kind of risk it carries. Each meter pulls from page signals, web reports, our AI analyst, vision, and the scam-network cluster — not from raw AV labels.
- AI analyst tagged this as crypto fraud / wallet-drainer.
- AI analyst tagged this as phishing.
0 of 13 categories showed signals
We check every URL against 13 distinct scam categories so the verdict tells you not just how risky the page is, but what kind of risk it carries. Each meter pulls from page signals, web reports, our AI analyst, vision, and the scam-network cluster — not from raw AV labels.
- AI analyst tagged this as crypto fraud / wallet-drainer.
- AI analyst tagged this as phishing.
Crypto scam / wallet-drainer indicators
The page shows patterns common to crypto-investment scams, fake airdrops, and wallet drainers.
- Do not interact with h-cl.top
Do not enter credentials, deposit money, download files, or install browser extensions from this site.
- Never paste your seed phrase anywhere
Legitimate wallets, exchanges and support staff will never ask for your 12/24-word recovery phrase. Typing it into any website — even one that looks real — gives attackers full access to your funds.
- If you already connected a wallet
Revoke token approvals immediately using revoke.cash or Etherscan's Token Approvals tool. Move remaining funds to a fresh wallet (new seed phrase). Assume the original wallet is compromised.
- OpenReport the wallet and URL
File a report at IC3 (FBI Internet Crime Complaint Center) or your country's cybercrime portal. Recovery is unlikely, but reports help law enforcement map the network.
Reputation Sources
How this domain rates across independent threat-intelligence and blocklist providers.
Safety FAQ
Common questions about this site, answered from the scan data on this page. These are auto-generated — not hand-written — so they always match the underlying report.
- Our automated security review flags h-cl.top as dangerous. Multiple threat indicators were detected — treat the site as a scam until proven otherwise.
- No — h-cl.top scored 13/100 on our trust scale. We detected active threat indicators, so we recommend avoiding the site entirely.
- h-cl.top is 11 months old, registered on 6/3/2025 through NameSilo,LLC. Scam domains are often freshly registered — a site under 6 months old warrants extra caution.
- 2 out of 92 antivirus engines in our malware network flagged h-cl.top as malicious or suspicious (2 outright malicious). Even one detection is a meaningful signal.
- No. h-cl.top is not currently listed on the major browser blocklist feeds that modern browsers use.
- We cache results for 24 hours. Signed-in MalwareTips members can trigger a manual rescan at any time using the "Rescan" button on the report page, which re-runs every check from scratch and refreshes this page.
User reviews & comments(0)
Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.