Gridinsoft Logo

Prunebit.com Review: Suspicious Website

August 30, 2026 at 3:31 AM
Suspicious Website
Checked by Website Reputation Checker
Table of Contents
Danger Zone
Risky Territory
Caution Advised
Trusted but Verify
Safe & Secure

Prunebit → Safety Check

First checked August 18, 2026 at 1:53 PM
Website content and technical signals analyzed
Method: automated checks.
This company has verified ownership of the profile and can respond to reviews.
Suspicious Website Gridinsoft currently classifies this site as Suspicious Website. The report highlights 12 blacklist detections, a very young domain (49 days), and phishing-related signals.
Trust signal radar Normalized trust signals for prunebit.com Domain Maturity: 49 days Domain Maturity Warning Cleanliness: 12 detections Warning Cleanliness Safety Level: 5 negative tags, 2 warning signals Safety Level Positive Signals: 1 positive signals Positive Signals Popularity: Estimated low traffic without Tranco or social profile data Popularity Trust Zone: .com Trust Zone Operational Signals: 0 detected services Operational Signals Location Credibility: Hosting country MA Location Credibility
Figure 1. Trust signal radar for prunebit.com. Larger shaded area indicates stronger trust signals.

How we scored prunebit.com

On-page mentions:
Cryptocurrency
Tech signals:
Multilanguage, GitHub Profile
Negative signals:
  • security-provider warnings
  • multiple malware or phishing blacklist detections (12)
  • phishing-style impersonation signals
  • heuristic signals associated with phishing
  • automated caution checks
  • a relatively new domain (49 days)
  • wallet-secret handling still contradicts the local-only claims
  • published administrator code still provides operator-side mnemonic access
Positive signals:
Context signals:
  • cryptocurrency content needing verification
  • standard payment methods
Last checked August 30, 2026 at 3:31 AM by Gridinsoft Trust Model v2.5.3
Independent Gridinsoft analysis

What Gridinsoft observed on Prunebit.com

A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.

Current review Review ID GMA-20260825041930-82c6dce1
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
Suspicious Website
Evidence basis
First-party site analysis External vendor intelligence: Context only — not used for this decision

The current independent first-party review classifies prunebit.com as a Suspicious Website with high confidence. PruneBit corrected its prior reserve and audit representations, but the critical wallet-secret issues remain: current client code still sends complete seed phrases, private keys, and PINs to server endpoints, while current pages say that the wallet is local and non-custodial and that those secrets are never readable by the operator. Public administrator code still implements a workflow to return and display a selected wallet's mnemonic. No specific malware payload, malicious APK execution, confirmed victim, confirmed theft, or transaction was established. Therefore the evidence supports a suspicious classification, not a claim that a cryptocurrency scam or distinct malware sample was proven.

Analyst findings

  • Critical 2
  • Info 2
  1. Critical

    Wallet-secret handling still contradicts the local-only claims

    The current public client still sends complete seed phrases, private keys, and PINs to server endpoints while PruneBit says that the wallet runs entirely in the browser, that data stays local, and that those secrets are never readable by the operator. This is a material security contradiction for a cryptocurrency wallet.

  2. Critical

    Published administrator code still provides operator-side mnemonic access

    The public administrator-interface code still contains an intended workflow to request, receive, display, and copy the mnemonic for a selected wallet. That capability remains incompatible with the current statement that seed phrases and PINs are never readable by the operator.

  3. Info

    Reserve and audit representations were corrected

    The current public APIs no longer claim large reserve balances, a named audit, or active certifications. This resolves those two prior evidence issues, but it does not resolve the wallet-secret handling and administrator-access contradictions.

  4. Info

    Domain reputation labels are not a verified malware sample

    Public OSINT contains domain-level reputation and scanning records, while the exact APK hash had no indexed search result. The review did not establish a specific malware payload, malicious APK execution, confirmed victim, theft, or transaction. The suspicious verdict follows from the current first-party wallet-secret contradictions, not from a claim that a separate malware sample was found.

Review 6 documented observations View evidence
01 Content

The apex and www hosts returned the same current page. PruneBit still describes itself as a non-custodial wallet running entirely in the browser, says that wallet data stays local and that keys stay on the user's machine, and states that seed phrases and PINs are never readable by the operator or anyone else.

  • HTTP status 200
  • Public artifact URL https://prunebit.com/
  • Public artifact URL https://www.prunebit.com/
  • Public artifact URL https://prunebit.com/privacy.html
  • Page element PruneBit is a secure multi-coin wallet Non-Custodial that runs entirely on your browser.
  • Page element Your keys stay on your machine.
  • Page element Your seed phrase and PIN never leave your device unprotected — they are encrypted with AES-256-GCM and are never readable by us or anyone else.
  • File SHA-256 ea2d049725118b105f7b6715f841aa73f60e0e55eb6e432bc4c51d3a69dc4fe1
  • File SHA-256 c167e8ca0fc924a8b82e7ffec34f9c2144dd90dc5f38e2d01b73c66702fd0d11
02 Form

The current import client still constructs a request containing the complete mnemonic and PIN for POST /api/import. Its private-key flow still constructs a request containing the complete private key and PIN for POST /api/import_private_key. The reviewed client code does not apply a separate client-side encryption envelope to those values before constructing the requests.

  • HTTP status 200
  • Public artifact URL https://prunebit.com/import.html
  • Analyst observation The current client code JSON-serializes mnemonic and password for POST /api/import.
  • Analyst observation The current client code JSON-serializes privateKey, coin, and password for POST /api/import_private_key.
  • Analyst observation No real seed phrase, private key, PIN, wallet, or funds were submitted.
  • File SHA-256 bd98c1f45073509be5126e337d233d13340f5520cbc719eb04090b092de7a550
03 Content

The publicly retrievable administrator-interface source remains unchanged from the prior review. It still provides a workflow that sends a selected wallet identifier and administrator secret to POST /api/admin/decrypt_seed, receives a mnemonic, displays it, and enables copying it.

  • HTTP status 200
  • Public artifact URL https://prunebit.com/admin_wallets.html
  • Analyst observation The reviewed administrator-interface code posts wallet_id and secret_key to /api/admin/decrypt_seed and displays data.mnemonic on success.
  • Analyst observation No administrator authentication or seed-decryption request was attempted.
  • File SHA-256 93389e0dfdf8df6c6b48cdfa3b6e7f968c4201cdc7f536ad6020e414202da772
04 Content

PruneBit corrected two material assurance problems from the prior review. The proof-of-reserves API now says that the service is non-custodial, makes no reserve claim, and lists no cold wallets. The security-audit API now says that no independent third-party audit has been completed and lists no certifications. The former advertised report paths still return HTTP 404, but the current APIs no longer present them as evidence.

  • HTTP status 200
  • Public artifact URL https://prunebit.com/api/proof-of-reserves
  • Public artifact URL https://prunebit.com/api/security-audit-info
  • Page element PruneBit is a non-custodial wallet: it never holds user funds, so no reserve backing is required or claimed.
  • Page element No independent third-party security audit has been completed yet. The codebase is open for public review.
  • HTTP status 404
  • File SHA-256 5ad241d0560bf7f91821cdfcda0ec5fd05913ede7d15a7efc690ee944f74d7b5
  • File SHA-256 3da9d1b19843ae17ed6bcfe4b75f1ae4d5837c78498fa49af5ca06158dd46fb1
05 Download

The site still serves the same 33,151,511-byte Android package as in the prior review. Its SHA-256 is unchanged. Exact public searches for that hash returned no indexed result. This is not a safety finding: the package was preserved by hash, but the current review did not establish a distinct malware payload or observed malicious execution from the package.

  • HTTP status 200
  • Public artifact URL https://prunebit.com/Prunebit_app.apk
  • MIME type application/vnd.android.package-archive
  • Analyst observation The downloaded package contained 33151511 bytes.
  • File SHA-256 91d9fd1c9c84936ff7897fa028de423fb186634201412f09c1effd65f87ad68a
  • Analyst observation No specific malware payload, observed malicious execution, confirmed victim, or confirmed theft was established.
06 Historical content

The exact ticket target is the registrable parent domain itself; the additional www host returned the same current page. URLScan indexed four public scans of the apex host from August 18 through 20 and none for www. A stored public view described the URLScan result as score 0 and one VirusTotal warning out of 91. OTX exposed four pulse references, all from PhishDestroy feeds rather than four independent sources. Exact Wayback apex and www lookups returned no saved HTTP 200 HTML snapshot.

  • Public artifact URL https://urlscan.io/domain/prunebit.com
  • Public artifact URL https://otx.alienvault.com/indicator/domain/prunebit.com
  • Public artifact URL https://phishdestroy.io/domain/prunebit.com/
  • Public artifact URL https://web.archive.org/web/*/https://prunebit.com/
  • Analyst observation These public results are domain-level reputation or scan records; they do not identify a separately verified malicious APK sample, exact harmful URL, or observed wallet-theft transaction.

Scope and limitations

  • The review covered the apex and www hosts, current public pages, client and administrator-interface code, public APIs, the downloadable Android package, DNS, TLS, public reputation indexes, URL-scan records, threat-intelligence references, and exact archive lookups at the recorded time.
  • No real seed phrase, private key, PIN, wallet, transaction, or funds were submitted. The finding concerns the sensitive values explicitly placed in the current client requests.
  • No administrator authentication or seed-decryption request was attempted. The operator-access finding concerns the capability explicitly implemented in the current publicly retrievable administrator-interface source.
  • The Android package was preserved and compared by hash but was not executed in this review. Absence of an indexed exact-hash result does not establish that the package is safe.
  • The exact ticket target prunebit.com is also the registrable parent domain. The www alias returned the same page; no separate user-supplied subdomain, path, or destination was available for a different object-specific verdict.
  • External reputation results are separately controlled, mostly domain-level, and time-sensitive. They were recorded as context and did not determine this first-party verdict.

What is Prunebit?

According to its current page title, prunebit.com presents itself as “PruneBit - Secure Multi-Coin Wallet”. The sections below evaluate the site-specific reputation and technical findings.

Figure 2. Website screenshot for Prunebit.com. 2026-08-30 06:31:11
This domain was registered July 19, 2026 at 11:53 PM through the company NameCheap, Inc. and had the owner Gridinsoft privacy protected.

Is prunebit.com safe?

Use caution with prunebit.com. Its current Gridinsoft trust score is 1/100; review the site-specific findings below before use.

Why is prunebit.com marked "Suspicious Website"?

Gridinsoft's current assessment of prunebit.com is based on phishing indicators, automated caution checks, and heuristic signals associated with phishing. Context considered alongside those findings includes a short domain history (49 days old) and limited public traffic history. Verified ownership of the Gridinsoft business profile is a positive signal. The listed status means the domain currently appears in Gridinsoft's own Threat List; it is not a consensus of external providers. 12 of 30 publicly displayed security sources report a warning. A separate license-restricted partner security signal also contributes to the automated assessment; its provider name and verdict cannot be displayed publicly under the source license.

Prunebit Digital Footprints

A structured view of the site's detected themes, page signals, and related online footprint elements.

Cryptocurrency

This website references cryptocurrency transactions or educational content related to digital assets such as Bitcoin, Ethereum, or other blockchain-based currencies.

Reliable Payment Method

Payment processing utilizes established and secure payment systems including major credit cards, PayPal, or other recognized financial service providers. These payment methods typically offer fraud protection and dispute resolution mechanisms to safeguard consumers.

APK Downloads

This site distributes APK files for Android apps or games outside standard app stores.

Bootstrap Framework

This site uses Bootstrap, a widely-adopted open-source framework for responsive web development. Bootstrap enables efficient creation of mobile-friendly interfaces through standardized components and styling.

Multilanguage

The website provides multi-language support, demonstrating international accessibility and commitment to diverse user populations. Multi-language implementation typically indicates professional development standards and global operational scope, representing a positive trust indicator.

Blacklisted by Security Providers

Security intelligence signal: A security-provider signal contributes to the automated assessment of prunebit.com. Publicly displayable provider verdicts, when available, are reported separately; some source details may be restricted by license.

Social Media Links

The presence of social media links on the website indicates that it references social media accounts. This signal alone does not confirm ownership or authenticity of those profiles.

GitHub Profile

This site links to a GitHub profile or public repository associated with the project. This is a useful transparency signal, especially when the account has public activity.

Phishing - High Risk

Automated analysis detected strong patterns on prunebit.com associated with phishing or brand impersonation. Exercise extreme caution and avoid entering passwords, verification codes, payment details, or personal information until legitimacy is independently confirmed.

Heuristic - Phishing
Heuristic Risk
Young Domain

This site was registered recently, which limits historical reputation data and long-term trust signals.

Listed by Gridinsoft

Gridinsoft Internet Security classified this site as unsafe. As a VirusTotal partner, our detections contribute to broader protection across tools and browsers.

Claimed Company Profile

The company behind prunebit.com has claimed its profile in the Gridinsoft portal and provided verified ownership details.

Color Guide
  • Requires special attention Marks high-risk findings that should be reviewed first.
  • Exercise caution Highlights areas involving user data, payments, or permissions.
  • Positive indicators Shows trust signals that support the site's reliability.
  • Neutral General context that does not increase or reduce risk on its own.

External provider warnings: 12/30 Suspicious Website

This section shows what independent external security sources say about this site.

A warning appears when one or more sources report malware, phishing, abuse, or other safety concerns. Each row shows the source and its verdict.

If no source reports a warning, the site is shown as clear in this section.

alphaMountain.ai
Phishing
Chong Lua Dao
Malicious
CRDF
Malicious
CyRadar
Phishing
Forcepoint ThreatSeeker
Phishing
G-Data
Phishing
Lionic
Phishing
SOCRadar
Phishing
Sophos
Malware
VIPRE
Malware
desenmascara.me
Malicious
BitDefender
Warned

External provider results for Prunebit.com, last checked August 30, 2026. — VirusTotal

Domain Information

Created July 19, 2026 at 11:53 PM Updated: August 19, 2026 at 9:22 PM · Expires: July 19, 2027 at 11:53 PM
Domain Age 49 days Recently Registered
Registrant Gridinsoft privacy protected IS (Iceland)
Registrar NameCheap, Inc. IANA ID: 1068
Abuse Email [email protected]
Domain Status Client Transfer Prohibited DNSSEC: UNSIGNED
Top Level Domain .com Generic TLD

Technical Details

IP Address 104.21.26.197
Hosting Provider AS13335 Cloudflare, Inc. San Francisco, California, US
SSL Certificate WE1 TLS 1.2 · Valid for: 3 months · from August 30, 2026 at 1:39 AM · to November 28, 2026 at 2:39 AM
Name Servers damon.ns.cloudflare.com
laura.ns.cloudflare.com

Content Analysis

Website title PruneBit - Secure Multi-Coin Wallet
Website description PruneBit - Secure multi-coin wallet supporting Bitcoin, Ethereum, Litecoin, Dogecoin and more. Full control of your crypto assets.
Primary Language
Profile
Prunebit · shop14 · 1 repos · 4.9 years
Mentioned hosts (5)
github.com api.coingecko.com api.qrserver.com cdn.jsdelivr.net prunebit.com

Security Analysis

Detection Signatures These signatures are used to generate the security fingerprint below.
Cryptocurrency Reliable Payment Method Bootstrap Framework Multilanguage Phishing - High Risk
Security Fingerprint Unique identifier based on site analysis

How to block Prunebit.com?

Our Anti-Malware can automatically block access to prunebit.com if it is flagged as malicious.

  1. Install and run the protection.
  2. The program will block flagged domains and remove related threats.

Exclusion

If you believe prunebit.com is safe, you can add it to the exclusion list:

  1. Open Gridinsoft Anti-Malware → Tools → Ignore List.
  2. Go to the Internet tab and add prunebit.com.

See detailed instructions for more options.

Are You the Owner?

If you own Prunebit.com and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.

Leave a review

Share your real experience with prunebit.com. Is it a trustworthy site, or did you encounter any issues? The more detail you provide, the more helpful your review is for others!

Publication Tip

- Your feedback helps us improve our security scores.
- Detailed reviews describing your real-life experience have a much higher chance of being published.
- Your email remains confidential.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your score for prunebit.com
1
points /100
The score is based on a 1-100 scale, with 100 being the most reputable.
Check another website
Verify the security of domains and services based on 10M+ real websites.
Is This Your Website?
Think your website was scored unfairly? Request a reevaluation and our team will take another look.
Flag for Reevaluation
Have you had a personal experience with Prunebit.com?
Share your thoughts and rate it to help others make informed decisions!
Is This Your Website?
Think your website was scored unfairly? Request a reevaluation and our team will take another look.
Flag for Reevaluation
Have you had a personal experience with Prunebit.com?
Share your thoughts and rate it to help others make informed decisions!