PhishDestroy Team · PhishDestroy

193,000+

Threats Tracked

Current report database

86,000+

Last Seen Active

Responded during the latest stored scan

107,000+

Unavailable at Last Check

Did not serve content during the latest stored scan

574

New in Last 24h

Featured Exposé · Registrar Retaliation

ICANN registrar got our X account banned after we exposed them defending a $20M+ crypto-theft operation. X's own automation cleared us. Ban held.

Forensic Pipeline

How Does Crypto Phishing Threat Intelligence Work?

The process moves from a single-pixel suspicion to a timestamped public evidence record. It maps seven stages, twenty-eight global partners, and a fourteen-hour median time to takedown in one operations view.

7Pipeline stages

28+Vendor partners

14hMedian TTM

Detection Pipeline

Threat-Intel · TTPs & Geo

The Threats We Hunt

Wallet DrainersSpear PhishingMalicious Smart ContractsIce PhishingGeo: Russia & CISGeo: NigeriaGeo: IndiaGeo: Turkey

⌘KLook up any domain in our 193,000+ threat database

LIVE

Detectedloading live feed…

Flagship

Six tools that do the heavy lifting

These are the core tools: live data, open APIs, domain analysis and on-chain intelligence. Access is free and unlimited.

REAL-TIME

Live Threat Feed

Stream of phishing detections as they happen: domain, brand, registrar, cloaking flags. Refreshed continuously.

Watch the feed →

193,000+ DOMAINS

Domain Intel Hub

Per-domain dossiers: WHOIS, DNS, TLS, VirusTotal, cloaking, kit fingerprint, abuse-report history. Searchable.

Browse reports →

NO API KEY

Free REST API

Check a domain, pull a feed, bulk-scan 500/req. 1M+ threat records, CC-BY licensed, zero cost.

Read API docs →

ONE-CLICK

URL Analyzer

Paste any URL to get VirusTotal consensus, drainer-kit fingerprint, cloaking test, SSL chain and a screenshot.

Analyze now →

ON-CHAIN

Phishing Wallets DB

Drainer addresses, rug-pull wallets, linked infrastructure across EVM + Solana. Flagged, searchable, exportable.

Search wallets →

OPEN SOURCE

DestroyList Blocklist

Community-curated threat feed on GitHub. Auto-updated domain blocklist for firewalls, DNS filters, browser extensions.

View on GitHub →

Platform Directory

Everything else we built

Supporting tools, research dashboards, guides and experimental projects, grouped by purpose.

scan@phishdestroy:~$

scan@phishdestroy:~$check --domain <target>

▸ instant verdict against 193,000+ tracked domains

▸ backed by /v1/check API • 0 API key required

They call us Enemy #1

Relentless Attacks. Zero Effect.

Scammers repeatedly target our infrastructure to escape reports and bans. The outcome stays the same: evidence remains public, detections continue, and our takedown reporting costs users $0.

Current corpus

193,000+

Domains tracked

Stored records

60,000+

Abuse reports

Confirmed outcomes

27,000+

Confirmed takedowns

Zero-fee policy

$0

Paid to registrars or platforms for takedowns (ever)

Warning: Crypto Scams Ahead

Knowledge is your best defense. Learn the most common deception tactics to avoid becoming the next victim.

Fake Returns Impersonation Sextortion Rug Pull Blackmail Ransomware Phishing

Fake Returns / HYIP

RED

High-yield investment scams promise unrealistic ROI (1–5% daily) and pay early depositors with new investor money. When inflow stops, the platform vanishes overnight.

Red flags

Guaranteed daily ROIReferral pyramid (5-tier)Withdrawal lock / feesWhitepaper plagiarizedAnonymous founders

$4.6BPlusToken Ponzi

715KVictims (CN/KR)

2019Collapsed

Case: PlusToken

PlusToken: Asian-region Ponzi disguised as a wallet/exchange app. Operators promised 6-18% monthly returns, accumulated ≈200K BTC + 800K ETH, then vanished. 109 arrests in 2020; ~$2.9B in BTC seized & burned.

Crypto Drainer Cases

Impersonation

VIOLET

Operators mimic exchange support, project founders, KOLs or wallet vendors. Contact via cold DM, replies under viral tweets, or fake verified handles to push fake giveaways, support tickets or recovery flows.

Red flags

DM-first contactVerified-handle clone (zero-width chars)Bot-amplified reply chainsFake support formENS look-alike (vita1ik.eth)

$85MPink Drainer haul

21,000+Drained wallets

May 2024Operator retired

Case: Pink Drainer

Pink Drainer: phishing-as-a-service kit weaponized by impersonation crews. Posed as Coinbase / OpenSea / Discord moderators, lured users to signature pages disguised as 'security verifications'. Hit Evan Luthra, OpenAI's Mira Murati and 21K+ retail wallets before public retirement.

How scam teams operate

Sextortion

AMBER

Mass-spammed extortion emails citing a leaked password (from old breaches like Collection #1, LinkedIn 2012, Adobe 2013) and claiming compromising webcam footage exists. Demand $500–$2,000 in BTC within 24–72h.

Red flags

Spoofed sender = your own emailOld breached password in bodyBTC address with deadlineNo actual proof / videoGeneric 'I hacked you' template

7M+Emails / year (FBI IC3)

$19MReported losses 2023

~3%Pay rate

Case: Aaron Smith-Hicks

Aaron Smith-Hicks / 'Webcam Hacker' wave (2018-2024): same template recycled across 30+ language variants. Operators recycle BTC addresses; chain analysis shows ≈99% of recipients never had actual footage. Ignoring + deleting the mail is the documented mitigation.

Protect yourself now

Rug Pull

VIOLET

DeFi devs deploy a token, seed liquidity, and hype it via paid KOLs and shillers. They then drain the LP pool or trigger a mint, blacklist, or transfer-fee backdoor in the contract before disappearing. Token price → 0 in minutes.

Red flags

Anonymous / KYC-less teamLP locked <12 months or unlockedMint / blacklist / setTax in contractUnverified contract on EtherscanHoneypot: you can buy, can't sell

$2.8BStolen 2023 (Chainalysis)

~70%New tokens = rug

$3.38MSquid Game token

Case: Squid Game token

Squid Game token / SQUID (Nov 2021): capitalized on Netflix hype, used a honeypot contract that blocked all sells. After mooning +75,000%, devs swapped all liquidity for BNB and vanished. Wallet trail led to OKX deposit. 40K+ holders bagged a zero.

Exposed: wallet drainer panels

Blackmail / Extortion

RED

Operators threaten DDoS, doxx, fake CSAM planting, or 'leaked source code' to extort crypto from businesses and individuals. Most threats are bluffs leveraging fear of disruption.

Red flags

24h ransom deadlineXMR / privacy-coin demandNo proof of capability shownThreatens 'leak to clients/press'Recycled boilerplate text

$1.1BRansomware 2023 (Chainalysis)

25%Victims who pay

~5 BTCTypical demand

Case: DD4BC

DD4BC / Armada Collective copycats (2020-2024): empty DDoS extortion against fintech, exchanges, casinos. Demand 5-50 BTC under threat of '500 Gbps attack'. Real DD4BC operators were arrested in 2016; every group using the name since is a copycat with no infrastructure.

What to do if threatened

Ransomware

RED

Operators breach via RDP, phishing or unpatched VPN, deploy encryption payload across the network, exfiltrate sensitive data, then demand BTC/XMR via TOR negotiation portal. Double-extortion = pay-or-leak.

Red flags

RDP brute-force on 3389Cobalt Strike beaconEncrypted .lockbit / .conti / .akira extTOR .onion negotiation portalSample leak on data-leak site

$1.1BPaid in 2023

$1.5MAvg payout

1,800+LockBit victims

Case: LockBit

LockBit (2019-2024) was a RaaS operation with a 20% affiliate fee. It hit Boeing, ICBC, and UK Royal Mail. Before Op Cronos seized its infrastructure in February 2024, LockBit had ≈1,800 confirmed victims and collected $120M+ in ransom. Same actors rebranded as ALPHV / RansomHub.

Build your digital fortress

Phishing / Wallet Drainers

GREEN

Most common vector. Fake versions of wallets, DEXes, mint pages, claim portals. Victim connects wallet, signs a permit2 / setApprovalForAll / increaseAllowance transaction. The drainer sweeps balance and ERC-20s instantly.

Red flags

Punycode domain (Cyrillic a → Latin a)'WalletConnect' popup outside dApppermit / setApprovalForAll signatureDiscord / X DM 'support agent'Free mint / airdrop urgency

$87M+Inferno Drainer haul

137,000Drained wallets

Nov 2023Operator shutdown

Case: Inferno Drainer

Inferno Drainer (2022-2023): drainer-as-a-service used by 100+ phishing crews. Provided wallet-draining smart contracts + UI kit; took 20% cut. Spawned 1,000+ phishing sites/day. Public shutdown in November 2023, but spinoffs (Angel, MS, Venom, Pussy, Rainbow Drainers) instantly took place.

Inside a drainer panel

Hacked? Do this first — emergency response for scam and drainer victims. Never share your seed phrase. SEAL 911, Security Alliance.

Don't Be Silent! Your Silence is Their Power.

If you've been scammed, file a report. Filing a report on platforms like Chainabuse is a minimum first step. Ideally, you should report the incident to your local law enforcement. For expert guidance on legal matters or theft, we highly recommend contacting Seal911. Its professionals can provide sound advice for your situation.

Be extremely cautious of "recovery services" that contact you after a theft. Most are recovery scams trying to victimize you a second time.

Threat Surface

Where scammers reach you

Three common delivery channels turn an ordinary search, reply, or support request into a phishing attempt.

Google Ads

HIGH

A sponsored result can imitate a wallet or exchange and lead to a lookalike domain.

X replies

HIGH

Impersonator accounts clone names and avatars, then post fake giveaways or support links.

Discord support

HIGH

Fake moderators send unsolicited DMs and ask you to open a ticket or reconnect a wallet.

Simple rule: never share a seed phrase or sign an unexpected transaction to "verify" a wallet.

See all scam channels

Connected Security

Security Tools and Partners

Open data, public reports and feeds built to work with other security tools.

350K+

Domains Analyzed

54+

Security Vendors

17M+

Flagged Wallets

For Developers

Destroy API

Free, open, no API key. Real-time domain risk scoring across 1M+ threats.

Endpoints

5

Bulk Limit

500 /req

Auth

Open

Sync

Hourly

api.destroy.tools

$ curl "https://api.destroy.tools/v1/check?domain=suspicious-site.xyz"

{

"threat": true,

"risk_score": 85,

"severity": "critical",

"sources": ["destroylist", "community"],

"dns_active": true

}

Threat Scoring (0–100)

Critical 70–100High 40–69Medium 20–39Low 1–19

Available Endpoints

API Endpoints
MethodEndpointDescription
GET/v1/check?domain=Single check
POST/v1/check/bulkBulk (500/req)
GET/v1/search?q=Keyword search
GET/v1/feed/{list}Full feeds
GET/v1/statsLive stats

Live Intelligence

Latest Detections

Recently stored phishing detections from the public feed.

Protect Yourself

Essential Security Resources

Emergency: I Was Scammed

Immediate steps if your crypto wallet was drained. Revoke approvals, secure remaining assets, and report the crime.

Emergency Response Guide

Ultimate Security Checklist

Step-by-step guide to hardening your crypto security. Hardware wallets, 2FA settings, and browsing hygiene.

Security Checklist

Privacy Arsenal & Tools

Recommended privacy tools, secure browsers, VPNs, and operating systems to stay anonymous online.

Privacy & Security Tools
Security illustration showing threat neutralization

What we do

A Free Solution to Take Down Scammers

We follow threats from initial detection through infrastructure takedown.

Cooperation with Authorities

We help identify scam teams and prepare reports that law enforcement can use.

Threat Chain Tracing

We reconstruct threat chains across multiple domains, assets, and wallets.

Code Analysis & Auto-Detection

We build detection templates and automate code analysis to instantly block scams.

Hall of Shame

Eliminated Operations

  • PinkDrainer
  • InfernoDrainer
  • MS Drainer
  • CrazY Evil
  • AceDrainer
  • SmolGoblin
  • CryptoLove
  • Gambler
  • Keitaro TDS

Hacker's Cry

Yo, it's Morgan, your PinkDrainer king with the Pinkboy! password! Chillin' at some address - until the UK cops crashed my party! They've got me locked up, but ha, I'm still hugging my glittery crypto stash tight - good luck prying it from my pink fingers! 2 stars for the arrest, you pesky hunters!

Hacker's Rant

Oh, behold Inferno Drainer, ghost who vanished then strutted back! 'big hits' were just backdoor thefts. It turns out Angel Drainer sold me off ages ago and played puppet master, tricking his crew with my name! Now I'm toast, and my crypto's gone - well done, you sly hunters, 4 skulls for the expose!

Hacker's Meltdown

Well, hello there, it's Phishlab - aka Pakulichev, the coding genius! Sold my MS Drainer code for $1,500 to 200 clowns who leaked, resold, and wrecked havoc! Now my masterpiece's racked up $60 million+ in damage, and I'm sitting here with peanuts in my pocket - brilliant move, eh? Time to cry into my empty wallet while you lot laugh!

Hacker's Whine

Hey, it's your crew CrazY Evil, still ruling the scam scene! Angel Drainer's our real-life bro since way back - we even collabed, dropping Russian rap about scams, loving to smear the beats! But he bailed - hated how we snatch all the profit and leave workers no control, unlike his tidy Drainer setup. He's chilling in Some Hot country, sipping tea, while we keep the chaos rolling - catch us if you can!

Hacker's Panic

Ha! It's AceDrainer, the pop-up wizards still on the loose! We hacked those animation libraries, flooding crypto apps with sneaky pop-ups - draining wallets like champs! Sure, our domains are getting auto-banned left and right, but we're dodging you lot for now. Keep trying, you clever detectors - 2 bans for your effort!

Hacker's Beg

Ha! It's C*** D** Loy, aka SmolGoblin, the UA scam king! Ripped off 1,000+ suckers worldwide, pocketing over $10 million - heck, one some country fool lost $2.7 million ($20M at today's rate)! Phishing, laundering via some exchange, spreading "Stealername" malware, and cruising in my Maybach S580, Tesla Model X, BMW M4 Competition, and Porsche 911! Czech cops are sniffing around. Nah, I'll race 'em instead! Catch me if you can, you legal nerds!

SmolGoblin

Hacker's Surrender

Yo, it's the late CryptoLove crew, once the love bandits of crypto! Thought our phishing game was unstoppable - until RussianPanda swooped in like a ninja bear! He torched our domains, drained our wallets, and left us crying in the dust. Game over, you sly panda bastard - 5 skulls for the knockout, we're donezo!

Scammer's Delusion

Hey hey, it's your boy from Gambler Panel! I totally don't steal from my own workers - pinky promise! I'm basically a charity, right? Just scamming the entire CIS and half the world, no biggie. Love my party supplies more than my own projects! And those designs with rainbows and pride flags? Dead serious, not trolling at all! Big thanks to PhishDestroy for banning all my worker domains - really helps with my reputation! As a truly gifted leader, I'm proud that my panels rack up 15+ VirusTotal detections. That's called quality!

Arakelyan L. A. · Russia, Moscow Oblast, Domodedovo

Product's Confession

Huge thanks to PhishDestroy for the thorough audit and that lovely GitHub script that detects Keitaro on any site! Our beloved TDS product is mostly used for phishing, scam, malware distribution, and cloaking - but hey, we call it "traffic management"! Zero login page protection out of the box? That's a feature, not a bug! We're the #1 cause of domain bans worldwide and we love it. Money and lockers are our true passion - definitely a legal company that absolutely doesn't collect black market traffic data!

Disclaimer: All characters in this section are fictional and presented in a humorous, parody style for entertainment purposes only. They are not connected to any real individuals. Inspired by public nicknames and open cases, with no personal data or direct accusations included.

Support & Legal

Disclaimer and Frequently Asked Questions

Non-commercial, independent project. We are an open community focused on identifying, documenting, and disrupting phishing and scam infrastructure for public benefit.

  • Open by design. Where safe and lawful, indicators and scans are publicly accessible.
  • No user databases. We do not store personal data. For appeals and takedown status we use a ticket ID only.
  • No direct takedowns. We submit evidence to registrars, hosting providers, and trusted vendors; enforcement is their decision.
  • Safe for legitimate sites. Our passive scans and reports do not harm lawful resources.
  • No warranties. Content is provided "as is", without guarantees of completeness or fitness.
  • Lawful cooperation. For qualifying cases, artifacts may be shared with competent authorities.

  • Scanning. We perform safe, passive checks to collect artifacts and indicators.
  • Escalation. We request professional services to verify resources and ask registrars/hosts to review clients via abuse teams.
  • Investigations. We occasionally conduct limited, evidence-led OSINT; results are published, shared with peers, or forwarded to authorities. We do not hoard private data. See our Gambler Panel investigation for an example. Browse all research on our News & Investigations page.
  • Collaboration. We are open to partnerships. Certain private tools and materials can be shared for defensive purposes on request.
  • Dashboards. Explore stolen funds across all chains via the DeFi Hack Explorer or investigate scam infrastructure with our Scam Intelligence Dashboard.

Permanent public allowlist. Cleared domains are added to our permanent allowlist. The public list is available as allowlist.json.

Appeal removes the domain. If an appeal is approved, the domain is removed from our database and from any places where we published it.

Ticket-only tracking. We do not store personal data. For status checks and takedown requests we use a ticket ID only.

  • Open access. The bot is open to everyone, which does not change its purpose: faster disruption of fraud.
  • No paid leniency. We have never asked for or accepted payment for unbans or favors. The process and database are open and verifiable.
  • Trusted reporters. Reputable users may report without pre-moderation and submit bulk complaints for speed.

Act fast and preserve evidence: URLs, TXIDs, wallet addresses, screenshots, timestamps, chat logs. File an official report. For prevention, read our Crypto Security Essentials guide.

  • United States: https://www.ic3.gov/
  • United Kingdom: https://www.actionfraud.police.uk/
  • Other countries: contact your national cybercrime unit or local police

Independent incident-response resource

For any incident, I strongly recommend contacting the SEAL 911 Bot. SEAL 911 is an independent Security Alliance service for eligible active crypto incidents. Review its scope before sharing case details. PhishDestroy does not recover funds, provide private recovery advice, or accept recovery payments.

Read the original on phishdestroy.io ↗