SUSPECTED SCAM!

Phishing
proxy-828e451c.odylicast.workers.dev

Date09/17/2026
Url / Websitehttps://proxy-828e451c.odylicast.workers.dev
Scamdoc Trust Score | Contact / Whois info
Scam contentsCrypto wallet-drainer command-and-control plus injected DeFi lure. C2 is a Cloudflare Worker at https://proxy-828e451c.odylicast.workers.dev (sibling pattern proxy-[8 hex].odylicast.workers.dev). The Worker accepts POSTs of AES-GCM ciphertext (Content-Type: text/plain) and returns drain plans (fetch.scan) including unlimited ERC-20 approve and USDC EIP-2612 permit. Lure: https://app.nado.finance/ injects a Reown/AppKit clone wallet picker. ETH receiver/spender 0xe5ea610a7b0141df4e0c312dbf0ec7731fc36104. Base C2 pointer 0x623f65e5945c0fecf8f68ff9d98ce56fece6bc6a selector 0x3bc5de30. Please sinkhole the Worker hostname, warn on the lure URL, and freeze the steal addresses. This is a drain kit (wallet_sendCalls / permit), not a password phish.
Comment / Reviewwallet drainer C2 / injected lure

Premium services