Threat Intelligence Hub

Phishing Intelligence & Investigations

Real-time threat intelligence, active investigations, and takedown operations from our detection systems.

Updated daily 183,537 domains tracked Active takedowns
LIVE THREATS
183,000+Domains Tracked
27,000+Takedowns
24/7Monitoring
<15minAvg Response
Hacked? Do this first — emergency response for scam and drainer victims. Never share your seed phrase. SEAL 911.
Hacked? Do this first.Emergency response for scam & drainer victims — never share seed phrases.

Latest Security Updates

Investigations, research, and takedown operations

The Seed Was Valid. The RNG Was Broken.
#CaseFile#WeakRNG#WalletSecurity

The Seed Was Valid. The RNG Was Broken.

Coldcard, Trust Wallet and Libbitcoin produced valid wallet seeds from dangerously small keyspaces. Read the evidence and check how yours was generated.

Interactive case file
A technical flow from threat detection through evidence validation to accountable DNS abuse response
#Whitepaper#DNSGovernance

From Detection to Enforcement: A Measurable Framework for DNS Abuse Response

Measurable DNS abuse response: proportionate action, transparent decisions, safeguards and rapid appeals.

Technical whitepaper
UltaHost Abuse: Not Us, But a Great Takedown
#STATEMENT#ULTAHOST#REGISTRAR

UltaHost Abuse: Not Us, But a Great Takedown

Some readers attributed ultahostabuse.com to PhishDestroy based on its visual style. We found no evidence for that attribution. Its registrar-focused research remains an independent source and should be assessed on the evidence it publishes.

External statement
Registrar Accountability scoreboard — which domain registrars act on abuse reports and which ignore them
#Accountability#Registrars#ICANN#OpenData

Registrar Accountability — Who Acts on Abuse Reports

A live, evidence-based scoreboard built from every abuse report we send: confirmed-suspension rate, response times, repeat-report escalations, and how many reported domains each registrar never suspended. Deterministic, reproducible, MIT-licensed, updated daily.

Jul 10, 2026 Live data
We Are No Longer Volunteers — PhishDestroy editorial statement
#Editorial#Statement#Transparency

We Are No Longer Volunteers

Why we are retiring a word weaponized against the public interest — when ICANN (a $50M non-profit) and a decade-long wallet thief both call themselves “volunteers,” the word protects only the entities hiding behind it.

Editorial 5 min read
The Real Enemy Isn't the Scammer — It's the Registrar
#Registrar#ICANN#Op-Ed

The Real Enemy Isn't the Scammer. It's the Registrar.

An op-ed: scammers are cheap, replaceable foot soldiers. The scam economy runs on registrars that sell silence — and an ICANN that won't enforce. $16B lost in 2024; phishing up 180% since 2021. Make impunity expensive.

Jul 8, 2026 11 min read
NameSilo registrar evidence — 183K malicious domains
#Registrar#NameSilo#ICANN

NameSilo Evidence: 183K Malicious Domains Behind a Privacy Shield

Live dossier on NameSilo (IANA #1479). 5.27M domains scanned · 87.3% dead or parked · 183K malicious hidden behind their own privacy shield — filed with ICANN.

Updated daily 32 stars
NiceNIC registrar evidence — 18,927 malicious domains
#Registrar#NiceNIC#China

NiceNIC Evidence: 18,927 Malicious Domains in One Registrar

Full zone scan of NiceNIC (IANA #3765, China) — 349,376 domains, 18,927 confirmed malicious: phishing, carding, crypto drainers and gambling. IOC feeds + SIEM CSV.

Updated daily 13 stars
Trustname registrar evidence — 86% malicious
#Registrar#Trustname#ICANN

Trustname Evidence: 86% of Active Domains Are Malicious

Complete-zone scan of Trustname / Fewmoretaps OÜ (ICANN #4318) — 7,641 domains, 86% of all live content confirmed malicious. Phase II evidence package.

Updated daily 21 stars
ShortDot SA registry evidence — 6.2M domains across 7 abused zones
#Registry#ShortDot#Luxembourg

ShortDot Evidence: 6.2M Domains, 9.5% of Global Phishing

Full enumeration of ShortDot SA (Luxembourg) — 7 zones (.icu, .bond, .cyou, .sbs, .cfd, .buzz, .qpon), 6.2M domains and 51,670 brand-impersonation sites targeting Chase, Binance, MetaMask & Ledger. .bond ranks #3 worldwide for phishing. IOC feeds + daily updates.

Updated daily 38 stars

Explore Our Free Tools

Analyze domains, check wallets, scan URLs — all free, no registration.

All Tools Security Checklist Privacy Arsenal Emergency Help