Highscore 52 · flagged Sunday, September 6, 2026

robinhood-drop.fun

Appeared in the .fun zone on Sunday, September 6, 2026; by the end of that day the census found active website about crypto web3. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: robinhood
+30
TLD with a high abuse rate
matched: fun
+8
brand name at a retail registrar
matched: NICENIC INTERNATIONAL GROUP CO., LIMITED
+8
brand name at a watch-list registrar
matched: NICENIC INTERNATIONAL GROUP CO., LIMITED
+6
Registrar
NICENIC INTERNATIONAL GROUP CO., LIMITED
Nameserver provider
Nameservers
dns1.p09.nsone.net, dns2.p09.nsone.net, dns3.p09.nsone.net, dns4.p09.nsone.net
First-day state
active website
HTTP status
200
Page title
Solana Token · $TOKEN Solana Token Portal
Has a form
no
Brand echoed
robinhood

Model opinions

Second opinionlooks like phishingtarget: Robinhoodconfidence 68%· claude-opus-5

Domain 'robinhood-drop.fun' invokes the Robinhood brand for a fake token 'drop', and the page is an unconfigured airdrop-claim template ($TOKEN placeholders, empty contract/market fields) whose only action is 'Open claim page' leading to a wallet-connect flow — the standard wallet-drainer shape, hosted on Netlify with a bulk registrar.

First passlooks like a scamconfidence 92%· claude-haiku-4-5

The domain 'robinhood-drop.fun' uses Robinhood's brand name to create false legitimacy, but the page itself is a Solana token airdrop scam with no legitimate connection to Robinhood. The page mimics a token claim portal and urges users to 'Open claim page' to connect wallets, a classic crypto rug-pull or token-theft attack pattern. Robinhood is not being impersonated on the page itself (no login form or credentials theft), but the domain name abuses the brand to lure victims to a fraudulent toke

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Sunday, September 6, 2026

Screenshot of robinhood-drop.fun taken by the zone census on 2026-09-06

Same data as JSON: /api/zone/domain/robinhood-drop.fun. This page is not indexed by search engines and does not link to the site it describes.