Independent · Public · Non-commercial · Since 2019

About PhishDestroy: Mission, Team & Methodology

We are an independent threat‑intelligence group. For 7+ years we have disrupted phishing, drainers, and crypto fraud. We detect live threats first, preserve evidence, and coordinate takedowns with hosts, registrars, and AV vendors.

193K+
Domains Tracked
60K+
Abuse Reports
27K+
Takedowns
869+
Targeted Brands
1M+
Public API Threats
$0
Non-Commercial
Live data · Updated every 30 minutes

PhishDestroy is an independent, non-commercial threat intelligence platform that detects phishing domains in real time, scores risk levels, preserves forensic evidence, and coordinates takedowns to protect users from phishing, cryptocurrency scams, and wallet drainer attacks. Active since 2019, the project tracks 193,000+ flagged domains across 869+ targeted brands, has filed 60,000+ abuse reports, and operates a public threat API and domain security database used by security researchers worldwide.

Who We Are

About PhishDestroy

When we see an active threat, we move immediately — not after victims appear, not after lawsuits. We act so there are no victims at all.

Our Mission & Methods

We began tracking Steam scammers and ad fraud in 2019. Today our scope spans global crypto phishing, wallet drainer networks, and large-scale fraud operations. We conduct end-to-end casework: tracing funds on-chain to real operators, mapping shared infrastructure, and linking campaigns to specific panels, keys, and source code.

Our edge comes from having studied scams from the inside — with full access to their infrastructure. That perspective lets us anticipate new attack variants before they launch at scale.

Our Uncompromising Principles

Non-Commercial

We sell nothing and take no donations. No paid delistings — ever. Revenue would corrupt our neutrality.

Public & Verifiable

Indicators, timestamps, and outcomes are published when safe and lawful. Every claim is traceable to evidence.

No Victim Data Stores

We avoid storing sensitive personal data. Reports use anonymised IDs. Victims control their own narratives.

Evidence Preservation

Web archives and forensic artifacts are retained so victims and investigators can access proof independently, long after takedown.

Lawful Cooperation

We coordinate with registrars, hosts, and AV vendors through proper channels and share artifacts with competent authorities when appropriate.

Zero Paid Delistings

Accepting payment to remove a detection is corruption. We have never done it and never will. Our integrity is not for sale.

How We Detect & Take Down Phishing

Our pipeline processes thousands of domains daily through automated scanning, multi-source intelligence, and expert review.

1. Detection

CT logs, DNS registrations, phishing feeds, community reports. Automated classifiers flag threats within minutes.

Search database

2. Analysis

VirusTotal (95 engines), WHOIS/DNS, SSL certs, screenshots, content analysis. Risk scores from 12+ signals.

Scoring methodology

3. Reporting

Evidence-backed reports to registrars and hosts — each stating the specific reason with facts, screenshots and documentation, reviewed before it is sent, not an automated notice — alongside distribution to AV vendors, browser safe-browsing, and community blocklists.

Anatomy of a Takedown

4. Takedown

Track each domain until dead. Evidence in web archives. Registrar response varies from hours to weeks.

Impact metrics

From Intelligence to Impact

Deep Investigations

We don't just find domains. We trace crypto on-chain, map infrastructure, and connect disparate campaigns to a single source, following the money to the operators.

"Root-Level" Access

We've seen scams from the inside. This unparalleled access to drainer panels, phishing kits, and operator infrastructure gives us a unique edge to preempt their next move.

Evidence Preservation

Every site is archived. We preserve crucial artifacts—JS encryption keys, operator IDs—creating an evidence locker for law enforcement and victims to use, no questions asked.

Proactive Disruption

We act so there are no victims. By reporting to over 50 vendors simultaneously, we create a network effect that dismantles scam campaigns before they fully launch. Learn more in our Anatomy of a Takedown guide.

Crypto-Scam Havens: The Responsibility Gap

A disproportionate number of crypto-scams originate from a handful of registrars. This is not a coincidence—it's a systemic failure in abuse handling.

Crypto-Scam Domains by Registrar

Source: PhishDestroy DB, live data

The Data Doesn't Lie

When one registrar hosts thousands more malicious domains than competitors, it points to a tolerance for abuse, incompetence, or both. Scammers flock to platforms with the least resistance.

Our Role

We provide clear evidence to these registrars, giving them the opportunity to meet their ICANN obligations. Our public logs create accountability when they fail to act.

Transparency & Trust

Credibility comes from openness. Every process is documented and verifiable.

Open Methodology

95 AV engines, 11 blocklists, DNS/WHOIS/SSL analysis. All documented.

How we score

Appeal Process

Every appeal reviewed within 48 hours. FP rate: <0.01%. No paid delistings.

Submit appeal

Public Data

Threat feeds, blocklists, investigation logs — open-source on GitHub.

GitHub

Evidence Retention

Screenshots, source code, WHOIS snapshots, Wayback archives for every domain.

Policy

Corrections Policy

Errors corrected publicly with timestamps and reasoning.

Policy

No Paid Delistings

We never accept payment to remove a detection. Integrity is non-negotiable.

Appeals

Editorial authorship

PhishDestroy Research

PhishDestroy Research is the collective editorial byline for evidence-led investigations, technical explainers and data reports published by PhishDestroy. PhishDestroy remains the publisher.

Browse research and investigations

Read our values and editorial principles
The full story · non-commercial since 2019Why we take zero money, stay radically transparent — and what we built in 2025–2026

A note before anything else: we are not looking for gratitude, recognition, PR, or reach. Visibility matters to us for exactly two reasons — pressuring registrars who ignore ordinary abuse emails, and permanently documenting their real position when they choose inaction.

Our adversaries

Our opponents are scammers. We often call them incompetent and unoriginal — and we stand by that. But we never underestimate their resources. The infrastructure that profits from scams commands significant money and reach, and a cornered rat will do anything: stolen funds get spent on takedowns of evidence sites, attacks on researchers, disinformation, smear attempts, fabricated accusations, and outright lies.

Why zero money — not one dollar

PhishDestroy is, and always will be, strictly non-commercial: no profit, no advertising, no paid services, no donations tied to outcomes. This is not idealism — it is a survival requirement.

  • Our style is aggressive and direct. Any financial dependency would be weaponized against us instantly.
  • Nobody notices when we're right, but every false positive would be amplified against us. Commercial interests would turn every mistake into an existential threat.
  • Independence is our only real armor. When a registrar like NameSilo threatens lawsuits, we don't weigh it against $60M in revenue — we just update our IPFS mirror and keep working.
Complete independence from money is possibly what makes us different.

Radical transparency

We aim to be maximally open in everything — our reports, our detection logic, our appeals process, appeal volumes and outcomes. We know all of it will eventually be used against us by registrars trying to justify their inaction. Fine. Let the record speak.

We make mistakes, and we are not afraid to admit them. We are not one person — we are a shared mission: the destruction of phishing and scam infrastructure, whether it's run by Russian, Nigerian, or Turkish crews. Nationality is irrelevant. Fraud is fraud.

The real value: evidence

We believe our core contribution is the evidence base. Something as simple as a site scan, a Web Archive snapshot, or a report submitted to an antivirus vendor carries real power:

  • It can become evidence for law enforcement.
  • It can become an IOC template for the security community.
  • It can help unmask a criminal's identity.
  • It can prove a registrar knew a site was malicious — and chose to violate its ICANN agreement anyway.

Victims deserve to see that the registrar was informed and ignored the threat.

“Scammers use you against competitors”

Do scammers report their rivals to us? Probably — we can't be certain. But think it through. When a scam site enters our pipeline we don't just block it: we fingerprint it, run domain-permutation analysis (dnstwist), and feed it into automated parsers covering SEO poisoning, Google Ads abuse, and other distribution channels. So yes — using us to destroy your competitor is an excellent choice. But when you deploy an identical site to take their place, you land in the same database. The logic holds either way.

Abuse of our system — and how we fixed it

There were real problems. “Takedown-for-hire” services abused our pipeline to attack gambling sites and stresser competitors. We rebuilt the system and banned those users:

  • We don't claim expertise in legitimate gambling — but scam gambling gets blocked.
  • Reports on gambling sites are only processed if backed by antivirus detections or partner blocklist entries.
  • Users who repeatedly submit only such sites receive warnings, then a ban.

The logic has matured significantly. Neither an admin nor a trusted user can submit, say, Coinbase and have it processed. We've built a strong AI layer and a substantial library of threat fingerprints, and the system keeps learning — it sees the gaps that existed and works to close them. Scammers will always attempt bypasses. That's expected.

Measurable impact

Even measured purely in burned domain costs, the damage we've inflicted on scam operations is substantial. More importantly: the era of phishing domains living for years is effectively over across nearly the entire crypto space — all the key terms, all the major brand-abuse patterns.

Since July 2025 we've also made the project genuinely public: a real website rather than a joke landing page, an open repository, documented processes — everything built so that anyone, especially victims, can verify what happened and who ignored what.

Get involved

The project keeps growing, and we hope it's useful. If you have ideas for improving the project or its tools, open an Issue on GitHub or submit a ticket via our Telegram bot. Any question, any proposal. We are non-commercial — but we actively cooperate with everyone who shares our goal: making the internet safer.

Credentials & Expertise

Why Trust Us — independent, verifiable expertise built over years of frontline threat research.

Certified Security Team
CISSP(ISC)² · 2026CCSPCloud Security · 2026OSCPOffensive SecurityGWAPTGIAC Web App Pen TesterBTL2Blue Team Level 2

Research-built, expert-driven defense — CISSP/CCSP-led, backed by OSCP, GWAPT, and BTL2 expertise. Supported by 7+ years of active work identifying and tracking scam and phishing threats.

Community Presence & Contributions

Every profile below is public and independently verifiable.

GitHub

Open-source threat intelligence tools, blocklists, and investigation logs.

PhishTank (Felix0101)

Active phishing URL reporter — thousands of verified submissions.

PhishTank (tuanphuong)

Community contributor to the PhishTank database.

AlienVault OTX

Threat intelligence pulses shared with the global security community.

HuggingFace DestroyList

ML-ready dataset of 189,000+ phishing domains for research and model training.

Mastodon

Real-time threat alerts and investigation updates.

Medium

In-depth writeups on phishing infrastructure, drainer panels, and scam economics.

X / Twitter

Breaking threat intelligence, takedown announcements, and community engagement.

Codeberg

Community-run Git mirror of our open blocklist and datasets — independent of GitHub.

A Message for Victims: Your Silence is Their Weapon

Do not stay silent. Do not hide what happened. By staying quiet, you protect the people who harmed you and set up the next victim. Your silence is their shield. More money for them means more infrastructure, more attacks, more victims. Break the cycle.

1. Get Immediate Help

For rapid response and professional help in any situation, contact the SEAL 911 team.

Contact SEAL 911

2. Report Publicly

The minimum you should do. Share information about the scammer with the world. It's a small step that can help others.

Report to Chainabuse

3. Report Legally

Report the crime to your local police department. This can be done via email or their website. Not reporting is covering for them.

Contact Local Police

A Message To...

The Industry

We are not your enemy. We are your free, expert abuse-triage service. Our reports are actionable intelligence, not accusations. We expect you to investigate and act as per your contractual obligations. If your abuse desk is unqualified, that is an internal issue. Requests for video proof or different file formats are intentional delays that help criminals steal more. Act on the comprehensive evidence we provide.

Scammers

Keep reporting each other. It helps us cluster and neutralize your networks faster. In 5/5 large CIS groups we analyzed, revenue filters skimmed funds from you upstream; you don’t even see 5% of the total take. You are not kings; you are disposable, and victims of your own operators.

Join the Mission

Use our data. Collaborate. Stop the next scam before it starts.