
The Seed Was Valid. The RNG Was Broken.
Coldcard, Trust Wallet and Libbitcoin produced valid wallet seeds from dangerously small keyspaces. Read the evidence and check how yours was generated.
Real-time threat intelligence, active investigations, and takedown operations from our detection systems.
Investigations, research, and takedown operations

Coldcard, Trust Wallet and Libbitcoin produced valid wallet seeds from dangerously small keyspaces. Read the evidence and check how yours was generated.

Measurable DNS abuse response: proportionate action, transparent decisions, safeguards and rapid appeals.

Some readers attributed ultahostabuse.com to PhishDestroy based on its visual style. We found no evidence for that attribution. Its registrar-focused research remains an independent source and should be assessed on the evidence it publishes.

A cartel wants the money, refuses outside regulation, and ignores its own contracts. Three toothless Trustname breach notices, one “inadvertently” unblocked card-stealing domain, a 60-day grace period — and $155M a year for it. RegisterFly, EstDomains, Epik, NameSilo: same pattern.

NameSilo first defended xmrwallet. After the wallet had already closed, PhishDestroy argues that the remaining campaign protected the registrar itself: overlapping SEO topics, review manipulation patterns, paid PR distribution, and attempts to remove individual search results — documented with 27 source articles and archived evidence.

A live, evidence-based scoreboard built from every abuse report we send: confirmed-suspension rate, response times, repeat-report escalations, and how many reported domains each registrar never suspended. Deterministic, reproducible, MIT-licensed, updated daily.

Why we are retiring a word weaponized against the public interest — when ICANN (a $50M non-profit) and a decade-long wallet thief both call themselves “volunteers,” the word protects only the entities hiding behind it.

An op-ed: scammers are cheap, replaceable foot soldiers. The scam economy runs on registrars that sell silence — and an ICANN that won't enforce. $16B lost in 2024; phishing up 180% since 2021. Make impunity expensive.

Live dossier on NameSilo (IANA #1479). 5.27M domains scanned · 87.3% dead or parked · 183K malicious hidden behind their own privacy shield — filed with ICANN.

Full zone scan of NiceNIC (IANA #3765, China) — 349,376 domains, 18,927 confirmed malicious: phishing, carding, crypto drainers and gambling. IOC feeds + SIEM CSV.

Complete-zone scan of Trustname / Fewmoretaps OÜ (ICANN #4318) — 7,641 domains, 86% of all live content confirmed malicious. Phase II evidence package.

Full enumeration of ShortDot SA (Luxembourg) — 7 zones (.icu, .bond, .cyou, .sbs, .cfd, .buzz, .qpon), 6.2M domains and 51,670 brand-impersonation sites targeting Chase, Binance, MetaMask & Ledger. .bond ranks #3 worldwide for phishing. IOC feeds + daily updates.

Monero leaves no blockchain trail. So we hunted differently. We injected 21 million decoy seed phrases into xmrwallet, burned 200K+ tweets as bait on X, and filed 11–12 abuse complaints NameSilo ignored on schedule. Every Medium article they deindexed, every DMCA they filed against us, every Twitter ban they triggered — logged by the receiving platform, timestamped, subpoenable. Same requester, same speed, same platforms — for both NameSilo and xmrwallet. That behavioral fingerprint is the case. "They thought they were silencing us. They were building our case."

@Phish_Destroy is banned on X. X's automated review: "no violation, account restored to full functionality." Account still gone. Two weeks earlier we exposed NameSilo sheltering a $20M+ crypto-theft operation with victims across multiple regions — now under active EU criminal investigation. Same playbook NameSilo ran for the scammer — weaponize a bureaucratic process — now running against us. Where's the paid gold-checkmark human support? Where's the unban the automation already granted? Where's our refund?

We flood active phishing forms with fake seed phrases. It buries the real victim submissions under thousands of decoys, poisons the drainer's credential pool, and forces the operator to sink hours triaging worthless data — often enough to abandon the campaign. This article explains why it works, how we do it responsibly, and why it is not illegal: no unauthorized access (the form is public and explicitly asks for input), no damage to legitimate systems (the site has no legitimate users), no violation of CFAA/Computer Misuse Act (feeding a public form deceptive data submitted voluntarily is not hacking). Full methodology, legal analysis, and real takedown results inside.
Analyze domains, check wallets, scan URLs — all free, no registration.