Google Ads
HIGHA sponsored result can imitate a wallet or exchange and lead to a lookalike domain.
Flagship
These are the core tools: live data, open APIs, domain analysis and on-chain intelligence. Access is free and unlimited.
Stream of phishing detections as they happen: domain, brand, registrar, cloaking flags. Refreshed continuously.
Watch the feed →Per-domain dossiers: WHOIS, DNS, TLS, VirusTotal, cloaking, kit fingerprint, abuse-report history. Searchable.
Browse reports →Check a domain, pull a feed, bulk-scan 500/req. 1M+ threat records, CC-BY licensed, zero cost.
Read API docs →Paste any URL to get VirusTotal consensus, drainer-kit fingerprint, cloaking test, SSL chain and a screenshot.
Analyze now →Drainer addresses, rug-pull wallets, linked infrastructure across EVM + Solana. Flagged, searchable, exportable.
Search wallets →Community-curated threat feed on GitHub. Auto-updated domain blocklist for firewalls, DNS filters, browser extensions.
View on GitHub →Platform Directory
Supporting tools, research dashboards, guides and experimental projects, grouped by purpose.
They call us Enemy #1
Scammers repeatedly target our infrastructure to escape reports and bans. The outcome stays the same: evidence remains public, detections continue, and our takedown reporting costs users $0.
Domains tracked
Abuse reports
Confirmed takedowns
Paid to registrars or platforms for takedowns (ever)
Knowledge is your best defense. Learn the most common deception tactics to avoid becoming the next victim.

If you've been scammed, file a report. Filing a report on platforms like Chainabuse is a minimum first step. Ideally, you should report the incident to your local law enforcement. For expert guidance on legal matters or theft, we highly recommend contacting Seal911. Its professionals can provide sound advice for your situation.
Be extremely cautious of "recovery services" that contact you after a theft. Most are recovery scams trying to victimize you a second time.
Three common delivery channels turn an ordinary search, reply, or support request into a phishing attempt.
A sponsored result can imitate a wallet or exchange and lead to a lookalike domain.
Impersonator accounts clone names and avatars, then post fake giveaways or support links.
Fake moderators send unsolicited DMs and ask you to open a ticket or reconnect a wallet.
Simple rule: never share a seed phrase or sign an unexpected transaction to "verify" a wallet.
See all scam channelsConnected Security
Open data, public reports and feeds built to work with other security tools.
For Developers
Free, open, no API key. Real-time domain risk scoring across 1M+ threats.
| Method | Endpoint | Description |
|---|---|---|
| GET | /v1/check?domain= | Single check |
| POST | /v1/check/bulk | Bulk (500/req) |
| GET | /v1/search?q= | Keyword search |
| GET | /v1/feed/{list} | Full feeds |
| GET | /v1/stats | Live stats |
Live Intelligence
Recently stored phishing detections from the public feed.
Protect Yourself
Immediate steps if your crypto wallet was drained. Revoke approvals, secure remaining assets, and report the crime.
Emergency Response GuideStep-by-step guide to hardening your crypto security. Hardware wallets, 2FA settings, and browsing hygiene.
Security ChecklistRecommended privacy tools, secure browsers, VPNs, and operating systems to stay anonymous online.
Privacy & Security Tools
What we do
We follow threats from initial detection through infrastructure takedown.
We help identify scam teams and prepare reports that law enforcement can use.
We reconstruct threat chains across multiple domains, assets, and wallets.
We build detection templates and automate code analysis to instantly block scams.
Hall of Shame
Disclaimer: All characters in this section are fictional and presented in a humorous, parody style for entertainment purposes only. They are not connected to any real individuals. Inspired by public nicknames and open cases, with no personal data or direct accusations included.
Support & Legal
Non-commercial, independent project. We are an open community focused on identifying, documenting, and disrupting phishing and scam infrastructure for public benefit.
Permanent public allowlist. Cleared domains are added to our permanent allowlist. The public list is available as allowlist.json.
Appeal removes the domain. If an appeal is approved, the domain is removed from our database and from any places where we published it.
Ticket-only tracking. We do not store personal data. For status checks and takedown requests we use a ticket ID only.
Act fast and preserve evidence: URLs, TXIDs, wallet addresses, screenshots, timestamps, chat logs. File an official report. For prevention, read our Crypto Security Essentials guide.
For any incident, I strongly recommend contacting the SEAL 911 Bot. This is a rapid response group of professionals who really know their stuff and can help in any situation.