About PhishDestroy: Mission, Team & Methodology
We are an independent threat‑intelligence group. For 7+ years we have disrupted phishing, drainers, and crypto fraud. We detect live threats first, preserve evidence, and coordinate takedowns with hosts, registrars, and AV vendors.
About PhishDestroy
When we see an active threat, we move immediately — not after victims appear, not after lawsuits. We act so there are no victims at all.
Our Uncompromising Principles
We sell nothing and take no donations. No paid delistings — ever. Revenue would corrupt our neutrality.
Indicators, timestamps, and outcomes are published when safe and lawful. Every claim is traceable to evidence.
We avoid storing sensitive personal data. Reports use anonymised IDs. Victims control their own narratives.
Web archives and forensic artifacts are retained so victims and investigators can access proof independently, long after takedown.
We coordinate with registrars, hosts, and AV vendors through proper channels and share artifacts with competent authorities when appropriate.
Accepting payment to remove a detection is corruption. We have never done it and never will. Our integrity is not for sale.
How We Detect & Take Down Phishing
Our pipeline processes thousands of domains daily through automated scanning, multi-source intelligence, and expert review.
1. Detection
CT logs, DNS registrations, phishing feeds, community reports. Automated classifiers flag threats within minutes.
Search database2. Analysis
VirusTotal (95 engines), WHOIS/DNS, SSL certs, screenshots, content analysis. Risk scores from 12+ signals.
Scoring methodology3. Reporting
Evidence-backed reports to registrars and hosts — each stating the specific reason with facts, screenshots and documentation, reviewed before it is sent, not an automated notice — alongside distribution to AV vendors, browser safe-browsing, and community blocklists.
Anatomy of a Takedown4. Takedown
Track each domain until dead. Evidence in web archives. Registrar response varies from hours to weeks.
Impact metricsFrom Intelligence to Impact
Deep Investigations
We don't just find domains. We trace crypto on-chain, map infrastructure, and connect disparate campaigns to a single source, following the money to the operators.
"Root-Level" Access
We've seen scams from the inside. This unparalleled access to drainer panels, phishing kits, and operator infrastructure gives us a unique edge to preempt their next move.
Evidence Preservation
Every site is archived. We preserve crucial artifacts—JS encryption keys, operator IDs—creating an evidence locker for law enforcement and victims to use, no questions asked.
Proactive Disruption
We act so there are no victims. By reporting to over 50 vendors simultaneously, we create a network effect that dismantles scam campaigns before they fully launch. Learn more in our Anatomy of a Takedown guide.
Crypto-Scam Havens: The Responsibility Gap
A disproportionate number of crypto-scams originate from a handful of registrars. This is not a coincidence—it's a systemic failure in abuse handling.
Crypto-Scam Domains by Registrar
Source: PhishDestroy DB, live dataThe Data Doesn't Lie
When one registrar hosts thousands more malicious domains than competitors, it points to a tolerance for abuse, incompetence, or both. Scammers flock to platforms with the least resistance.
Our Role
We provide clear evidence to these registrars, giving them the opportunity to meet their ICANN obligations. Our public logs create accountability when they fail to act.
Transparency & Trust
Credibility comes from openness. Every process is documented and verifiable.
Appeal Process
Every appeal reviewed within 48 hours. FP rate: <0.01%. No paid delistings.
Submit appealEvidence Retention
Screenshots, source code, WHOIS snapshots, Wayback archives for every domain.
PolicyNo Paid Delistings
We never accept payment to remove a detection. Integrity is non-negotiable.
AppealsEditorial authorship
PhishDestroy Research
PhishDestroy Research is the collective editorial byline for evidence-led investigations, technical explainers and data reports published by PhishDestroy. PhishDestroy remains the publisher.
The full story · non-commercial since 2019Why we take zero money, stay radically transparent — and what we built in 2025–2026
A note before anything else: we are not looking for gratitude, recognition, PR, or reach. Visibility matters to us for exactly two reasons — pressuring registrars who ignore ordinary abuse emails, and permanently documenting their real position when they choose inaction.
Our adversaries
Our opponents are scammers. We often call them incompetent and unoriginal — and we stand by that. But we never underestimate their resources. The infrastructure that profits from scams commands significant money and reach, and a cornered rat will do anything: stolen funds get spent on takedowns of evidence sites, attacks on researchers, disinformation, smear attempts, fabricated accusations, and outright lies.
Why zero money — not one dollar
PhishDestroy is, and always will be, strictly non-commercial: no profit, no advertising, no paid services, no donations tied to outcomes. This is not idealism — it is a survival requirement.
- Our style is aggressive and direct. Any financial dependency would be weaponized against us instantly.
- Nobody notices when we're right, but every false positive would be amplified against us. Commercial interests would turn every mistake into an existential threat.
- Independence is our only real armor. When a registrar like NameSilo threatens lawsuits, we don't weigh it against $60M in revenue — we just update our IPFS mirror and keep working.
Radical transparency
We aim to be maximally open in everything — our reports, our detection logic, our appeals process, appeal volumes and outcomes. We know all of it will eventually be used against us by registrars trying to justify their inaction. Fine. Let the record speak.
We make mistakes, and we are not afraid to admit them. We are not one person — we are a shared mission: the destruction of phishing and scam infrastructure, whether it's run by Russian, Nigerian, or Turkish crews. Nationality is irrelevant. Fraud is fraud.
The real value: evidence
We believe our core contribution is the evidence base. Something as simple as a site scan, a Web Archive snapshot, or a report submitted to an antivirus vendor carries real power:
- It can become evidence for law enforcement.
- It can become an IOC template for the security community.
- It can help unmask a criminal's identity.
- It can prove a registrar knew a site was malicious — and chose to violate its ICANN agreement anyway.
Victims deserve to see that the registrar was informed and ignored the threat.
“Scammers use you against competitors”
Do scammers report their rivals to us? Probably — we can't be certain. But think it through. When a scam site enters our pipeline we don't just block it: we fingerprint it, run domain-permutation analysis (dnstwist), and feed it into automated parsers covering SEO poisoning, Google Ads abuse, and other distribution channels. So yes — using us to destroy your competitor is an excellent choice. But when you deploy an identical site to take their place, you land in the same database. The logic holds either way.
Abuse of our system — and how we fixed it
There were real problems. “Takedown-for-hire” services abused our pipeline to attack gambling sites and stresser competitors. We rebuilt the system and banned those users:
- We don't claim expertise in legitimate gambling — but scam gambling gets blocked.
- Reports on gambling sites are only processed if backed by antivirus detections or partner blocklist entries.
- Users who repeatedly submit only such sites receive warnings, then a ban.
The logic has matured significantly. Neither an admin nor a trusted user can submit, say, Coinbase and have it processed. We've built a strong AI layer and a substantial library of threat fingerprints, and the system keeps learning — it sees the gaps that existed and works to close them. Scammers will always attempt bypasses. That's expected.
Measurable impact
Even measured purely in burned domain costs, the damage we've inflicted on scam operations is substantial. More importantly: the era of phishing domains living for years is effectively over across nearly the entire crypto space — all the key terms, all the major brand-abuse patterns.
Since July 2025 we've also made the project genuinely public: a real website rather than a joke landing page, an open repository, documented processes — everything built so that anyone, especially victims, can verify what happened and who ignored what.
Get involved
The project keeps growing, and we hope it's useful. If you have ideas for improving the project or its tools, open an Issue on GitHub or submit a ticket via our Telegram bot. Any question, any proposal. We are non-commercial — but we actively cooperate with everyone who shares our goal: making the internet safer.
Credentials & Expertise
Why Trust Us — independent, verifiable expertise built over years of frontline threat research.
Research-built, expert-driven defense — CISSP/CCSP-led, backed by OSCP, GWAPT, and BTL2 expertise. Supported by 7+ years of active work identifying and tracking scam and phishing threats.
Community Presence & Contributions
Every profile below is public and independently verifiable.
GitHub
Open-source threat intelligence tools, blocklists, and investigation logs.
PhishTank (Felix0101)
Active phishing URL reporter — thousands of verified submissions.
PhishTank (tuanphuong)
Community contributor to the PhishTank database.
AlienVault OTX
Threat intelligence pulses shared with the global security community.
HuggingFace DestroyList
ML-ready dataset of 189,000+ phishing domains for research and model training.
Mastodon
Real-time threat alerts and investigation updates.
Medium
In-depth writeups on phishing infrastructure, drainer panels, and scam economics.
X / Twitter
Breaking threat intelligence, takedown announcements, and community engagement.
Codeberg
Community-run Git mirror of our open blocklist and datasets — independent of GitHub.
A Message for Victims: Your Silence is Their Weapon
Do not stay silent. Do not hide what happened. By staying quiet, you protect the people who harmed you and set up the next victim. Your silence is their shield. More money for them means more infrastructure, more attacks, more victims. Break the cycle.
1. Get Immediate Help
For rapid response and professional help in any situation, contact the SEAL 911 team.
Contact SEAL 9112. Report Publicly
The minimum you should do. Share information about the scammer with the world. It's a small step that can help others.
Report to Chainabuse3. Report Legally
Report the crime to your local police department. This can be done via email or their website. Not reporting is covering for them.
A Message To...
The Industry
We are not your enemy. We are your free, expert abuse-triage service. Our reports are actionable intelligence, not accusations. We expect you to investigate and act as per your contractual obligations. If your abuse desk is unqualified, that is an internal issue. Requests for video proof or different file formats are intentional delays that help criminals steal more. Act on the comprehensive evidence we provide.
Scammers
Keep reporting each other. It helps us cluster and neutralize your networks faster. In 5/5 large CIS groups we analyzed, revenue filters skimmed funds from you upstream; you don’t even see 5% of the total take. You are not kings; you are disposable, and victims of your own operators.
Join the Mission
Use our data. Collaborate. Stop the next scam before it starts.
Our Key Research
Deep-dive investigations into phishing infrastructure, drainer panels, and scam networks.
XMRWallet Exposed
How a fake Monero wallet stole millions over 10 years through hijacked transactions.
TrustWallet Panel Exposed
Inside an $8.5M wallet drainer panel — leaked source code and 1,900 chat logs.
TheProject Scam Empire
Unmasking one of the largest coordinated scam operations with hundreds of domains.
Impact Metrics
193,000+ domains tracked, 60,000+ reports filed, 27,000+ takedowns coordinated.
Anatomy of a Takedown
Step-by-step walkthrough of how we take down phishing infrastructure.
Enemy One
Tracking down one of the most persistent phishing operators on the internet.
