Threat Intelligence Hub

Phishing Intelligence & Investigations

Real-time threat intelligence, active investigations, and takedown operations from our detection systems.

Updated daily 180,154 domains tracked Active takedowns
LIVE THREATS
180,000+Domains Tracked
27,000+Takedowns
24/7Monitoring
<15minAvg Response
Hacked? Do this first — emergency response for scam and drainer victims. Never share your seed phrase. SEAL 911.
Hacked? Do this first.Emergency response for scam & drainer victims — never share seed phrases.

Latest Security Updates

Investigations, research, and takedown operations

Scammers Are Not Hackers: 4 Backends Dissected
#Investigation#Firebase#Supabase#DaaS

Scammers Are Not Hackers: 4 Backends Dissected, All Trivially Compromised

4 live scam backends analyzed — Firebase with open Firestore rules, Supabase with full CRUD access, Express.js with zero auth, and a 19K-seed drainer campaign. All trivially deanonymizable.

Feb 18, 2026 18 min read
BUYTRX Exposed: TRON Approval Drainer Dissected
#Investigation#TRON#Drainer

BUYTRX Exposed: 55 Domains, Zero Auth APIs, and a TRON Approval Drainer Dissected

Full infrastructure teardown: 55+ phishing domains, unauthenticated APIs leaking victim data, on-chain drainer contracts, Google Ads funding, and Chinese-language operators exposed.

Feb 08, 2026 14 min read
xmrwallet.com Exposed: 10 Years of Stolen Monero Keys
#Investigation#Monero

xmrwallet.com Exposed: 10 Years of Stolen Keys & Hijacked Transactions

Forensic investigation: Monero web wallet leaks your private view key 40+ times per session via Base64 session tokens, then nullifies your transaction with raw_tx = 0. Operator identified.

Mar 16, 2026 14 min read
Why We Ban White Pages — Cloaking Explained
#Investigation#Cloaking#TDS

Why We Ban "White Pages" and Redirects to Official Sites — The Cloaking Problem Explained

How scammers use cloaking, white pages, and TDS systems to hide phishing from security scanners while targeting real victims. 50,000+ sites analyzed.

Mar 29, 2026 12 min read
Keitaro TDS: 1,500 Panels Exposed
#Investigation#Tool#Keitaro

Keitaro TDS: 1,500 Panels Exposed and Zero Legitimate Uses Found

50,000+ sites scanned, 1,565 admin panels discovered, 0% legitimate use rate. Criminal clients include EvilCorp, LockBit, and VexTrio. Open-source detection tools released.

Dec 10, 2025 10 min read
Scam Teams Compared: MercuryTeam, WasabiSquad, 717Team
#Investigation#ScamIntelLogs

Scam Teams Compared: MercuryTeam, WasabiSquad, and 717Team

The "middle class" of fraud exposed. Three teams, shared Google Spreadsheets, and proof that OSINT disruption works — 717Team archived after intelligence operations.

Oct 08, 2025 12 min read
TheProject: $10M Scam Mentorship Empire
#Investigation#Exposed#ScamIntelLogs

TheProject: Inside a $10M Scam Mentorship Empire

Not a scam tool — a scam university. $10M+ claimed, 5,000+ members trained since 2021. 730+ scammer usernames leaked. The upstream producer behind casino and drainer operations.

Sep 15, 2025 14 min read

Explore Our Free Tools

Analyze domains, check wallets, scan URLs — all free, no registration.

All Tools Security Checklist Privacy Arsenal Emergency Help