193,000+
Threats Tracked
Current report database
86,000+
Last Seen Active
Responded during the latest stored scan
107,000+
Unavailable at Last Check
Did not serve content during the latest stored scan
574
New in Last 24h
Featured Exposé · Registrar Retaliation
ICANN registrar got our X account banned after we exposed them defending a $20M+ crypto-theft operation. X's own automation cleared us. Ban held.
Forensic Pipeline
How Does Crypto Phishing Threat Intelligence Work?
The process moves from a single-pixel suspicion to a timestamped public evidence record. It maps seven stages, twenty-eight global partners, and a fourteen-hour median time to takedown in one operations view.
7Pipeline stages
28+Vendor partners
14hMedian TTM
Threat-Intel · TTPs & Geo
The Threats We Hunt
Wallet DrainersSpear PhishingMalicious Smart ContractsIce PhishingGeo: Russia & CISGeo: NigeriaGeo: IndiaGeo: Turkey
⌘KLook up any domain in our 193,000+ threat database
Detectedloading live feed…
Flagship
Six tools that do the heavy lifting
These are the core tools: live data, open APIs, domain analysis and on-chain intelligence. Access is free and unlimited.
REAL-TIME
Live Threat Feed
Stream of phishing detections as they happen: domain, brand, registrar, cloaking flags. Refreshed continuously.
Watch the feed →
193,000+ DOMAINS
Domain Intel Hub
Per-domain dossiers: WHOIS, DNS, TLS, VirusTotal, cloaking, kit fingerprint, abuse-report history. Searchable.
Browse reports →
NO API KEY
Free REST API
Check a domain, pull a feed, bulk-scan 500/req. 1M+ threat records, CC-BY licensed, zero cost.
Read API docs →
ONE-CLICK
URL Analyzer
Paste any URL to get VirusTotal consensus, drainer-kit fingerprint, cloaking test, SSL chain and a screenshot.
Analyze now →
ON-CHAIN
Phishing Wallets DB
Drainer addresses, rug-pull wallets, linked infrastructure across EVM + Solana. Flagged, searchable, exportable.
Search wallets →
OPEN SOURCE
DestroyList Blocklist
Community-curated threat feed on GitHub. Auto-updated domain blocklist for firewalls, DNS filters, browser extensions.
View on GitHub →
Platform Directory
Everything else we built
Supporting tools, research dashboards, guides and experimental projects, grouped by purpose.
scan@phishdestroy:~$
scan@phishdestroy:~$check --domain <target>
▸ instant verdict against 193,000+ tracked domains
▸ backed by /v1/check API • 0 API key required
They call us Enemy #1
Relentless Attacks. Zero Effect.
Scammers repeatedly target our infrastructure to escape reports and bans. The outcome stays the same: evidence remains public, detections continue, and our takedown reporting costs users $0.
Current corpus
193,000+
Domains tracked
Stored records
60,000+
Abuse reports
Confirmed outcomes
27,000+
Confirmed takedowns
Zero-fee policy
$0
Paid to registrars or platforms for takedowns (ever)
Warning: Crypto Scams Ahead
Knowledge is your best defense. Learn the most common deception tactics to avoid becoming the next victim.
Fake Returns Impersonation Sextortion Rug Pull Blackmail Ransomware Phishing
Fake Returns / HYIP
RED
High-yield investment scams promise unrealistic ROI (1–5% daily) and pay early depositors with new investor money. When inflow stops, the platform vanishes overnight.
Red flags
Guaranteed daily ROIReferral pyramid (5-tier)Withdrawal lock / feesWhitepaper plagiarizedAnonymous founders
$4.6BPlusToken Ponzi
715KVictims (CN/KR)
2019Collapsed
Case: PlusToken
PlusToken: Asian-region Ponzi disguised as a wallet/exchange app. Operators promised 6-18% monthly returns, accumulated ≈200K BTC + 800K ETH, then vanished. 109 arrests in 2020; ~$2.9B in BTC seized & burned.
Impersonation
VIOLET
Operators mimic exchange support, project founders, KOLs or wallet vendors. Contact via cold DM, replies under viral tweets, or fake verified handles to push fake giveaways, support tickets or recovery flows.
Red flags
DM-first contactVerified-handle clone (zero-width chars)Bot-amplified reply chainsFake support formENS look-alike (vita1ik.eth)
$85MPink Drainer haul
21,000+Drained wallets
May 2024Operator retired
Case: Pink Drainer
Pink Drainer: phishing-as-a-service kit weaponized by impersonation crews. Posed as Coinbase / OpenSea / Discord moderators, lured users to signature pages disguised as 'security verifications'. Hit Evan Luthra, OpenAI's Mira Murati and 21K+ retail wallets before public retirement.
Sextortion
AMBER
Mass-spammed extortion emails citing a leaked password (from old breaches like Collection #1, LinkedIn 2012, Adobe 2013) and claiming compromising webcam footage exists. Demand $500–$2,000 in BTC within 24–72h.
Red flags
Spoofed sender = your own emailOld breached password in bodyBTC address with deadlineNo actual proof / videoGeneric 'I hacked you' template
7M+Emails / year (FBI IC3)
$19MReported losses 2023
~3%Pay rate
Case: Aaron Smith-Hicks
Aaron Smith-Hicks / 'Webcam Hacker' wave (2018-2024): same template recycled across 30+ language variants. Operators recycle BTC addresses; chain analysis shows ≈99% of recipients never had actual footage. Ignoring + deleting the mail is the documented mitigation.
Rug Pull
VIOLET
DeFi devs deploy a token, seed liquidity, and hype it via paid KOLs and shillers. They then drain the LP pool or trigger a mint, blacklist, or transfer-fee backdoor in the contract before disappearing. Token price → 0 in minutes.
Red flags
Anonymous / KYC-less teamLP locked <12 months or unlockedMint / blacklist / setTax in contractUnverified contract on EtherscanHoneypot: you can buy, can't sell
$2.8BStolen 2023 (Chainalysis)
~70%New tokens = rug
$3.38MSquid Game token
Case: Squid Game token
Squid Game token / SQUID (Nov 2021): capitalized on Netflix hype, used a honeypot contract that blocked all sells. After mooning +75,000%, devs swapped all liquidity for BNB and vanished. Wallet trail led to OKX deposit. 40K+ holders bagged a zero.
Blackmail / Extortion
RED
Operators threaten DDoS, doxx, fake CSAM planting, or 'leaked source code' to extort crypto from businesses and individuals. Most threats are bluffs leveraging fear of disruption.
Red flags
24h ransom deadlineXMR / privacy-coin demandNo proof of capability shownThreatens 'leak to clients/press'Recycled boilerplate text
$1.1BRansomware 2023 (Chainalysis)
25%Victims who pay
~5 BTCTypical demand
Case: DD4BC
DD4BC / Armada Collective copycats (2020-2024): empty DDoS extortion against fintech, exchanges, casinos. Demand 5-50 BTC under threat of '500 Gbps attack'. Real DD4BC operators were arrested in 2016; every group using the name since is a copycat with no infrastructure.
Ransomware
RED
Operators breach via RDP, phishing or unpatched VPN, deploy encryption payload across the network, exfiltrate sensitive data, then demand BTC/XMR via TOR negotiation portal. Double-extortion = pay-or-leak.
Red flags
RDP brute-force on 3389Cobalt Strike beaconEncrypted .lockbit / .conti / .akira extTOR .onion negotiation portalSample leak on data-leak site
$1.1BPaid in 2023
$1.5MAvg payout
1,800+LockBit victims
Case: LockBit
LockBit (2019-2024) was a RaaS operation with a 20% affiliate fee. It hit Boeing, ICBC, and UK Royal Mail. Before Op Cronos seized its infrastructure in February 2024, LockBit had ≈1,800 confirmed victims and collected $120M+ in ransom. Same actors rebranded as ALPHV / RansomHub.
Phishing / Wallet Drainers
GREEN
Most common vector. Fake versions of wallets, DEXes, mint pages, claim portals. Victim connects wallet, signs a permit2 / setApprovalForAll / increaseAllowance transaction. The drainer sweeps balance and ERC-20s instantly.
Red flags
Punycode domain (Cyrillic a → Latin a)'WalletConnect' popup outside dApppermit / setApprovalForAll signatureDiscord / X DM 'support agent'Free mint / airdrop urgency
$87M+Inferno Drainer haul
137,000Drained wallets
Nov 2023Operator shutdown
Case: Inferno Drainer
Inferno Drainer (2022-2023): drainer-as-a-service used by 100+ phishing crews. Provided wallet-draining smart contracts + UI kit; took 20% cut. Spawned 1,000+ phishing sites/day. Public shutdown in November 2023, but spinoffs (Angel, MS, Venom, Pussy, Rainbow Drainers) instantly took place.
Don't Be Silent! Your Silence is Their Power.
If you've been scammed, file a report. Filing a report on platforms like Chainabuse is a minimum first step. Ideally, you should report the incident to your local law enforcement. For expert guidance on legal matters or theft, we highly recommend contacting Seal911. Its professionals can provide sound advice for your situation.
Be extremely cautious of "recovery services" that contact you after a theft. Most are recovery scams trying to victimize you a second time.
Threat Surface
Where scammers reach you
Three common delivery channels turn an ordinary search, reply, or support request into a phishing attempt.
Google Ads
HIGHA sponsored result can imitate a wallet or exchange and lead to a lookalike domain.
X replies
HIGHImpersonator accounts clone names and avatars, then post fake giveaways or support links.
Discord support
HIGHFake moderators send unsolicited DMs and ask you to open a ticket or reconnect a wallet.
Simple rule: never share a seed phrase or sign an unexpected transaction to "verify" a wallet.
Connected Security
Security Tools and Partners
Open data, public reports and feeds built to work with other security tools.
350K+
Domains Analyzed
54+
Security Vendors
17M+
Flagged Wallets
For Developers
Destroy API
Free, open, no API key. Real-time domain risk scoring across 1M+ threats.
Endpoints
5
Bulk Limit
500 /req
Auth
Open
Sync
Hourly
api.destroy.tools
$ curl "https://api.destroy.tools/v1/check?domain=suspicious-site.xyz"
{
"threat": true,
"risk_score": 85,
"severity": "critical",
"sources": ["destroylist", "community"],
"dns_active": true
}
Threat Scoring (0–100)
Critical 70–100High 40–69Medium 20–39Low 1–19
Available Endpoints
| Method | Endpoint | Description |
|---|---|---|
| GET | /v1/check?domain= | Single check |
| POST | /v1/check/bulk | Bulk (500/req) |
| GET | /v1/search?q= | Keyword search |
| GET | /v1/feed/{list} | Full feeds |
| GET | /v1/stats | Live stats |
Live Intelligence
Latest Detections
Recently stored phishing detections from the public feed.
Protect Yourself
Essential Security Resources
Emergency: I Was Scammed
Immediate steps if your crypto wallet was drained. Revoke approvals, secure remaining assets, and report the crime.
Emergency Response GuideUltimate Security Checklist
Step-by-step guide to hardening your crypto security. Hardware wallets, 2FA settings, and browsing hygiene.
Security ChecklistPrivacy Arsenal & Tools
Recommended privacy tools, secure browsers, VPNs, and operating systems to stay anonymous online.
Privacy & Security Tools
What we do
A Free Solution to Take Down Scammers
We follow threats from initial detection through infrastructure takedown.
Cooperation with Authorities
We help identify scam teams and prepare reports that law enforcement can use.
Threat Chain Tracing
We reconstruct threat chains across multiple domains, assets, and wallets.
Code Analysis & Auto-Detection
We build detection templates and automate code analysis to instantly block scams.
Hall of Shame
Eliminated Operations
Hacker's Cry
Yo, it's Morgan, your PinkDrainer king with the Pinkboy! password! Chillin' at some address - until the UK cops crashed my party! They've got me locked up, but ha, I'm still hugging my glittery crypto stash tight - good luck prying it from my pink fingers! 2 stars for the arrest, you pesky hunters!
Hacker's Rant
Oh, behold Inferno Drainer, ghost who vanished then strutted back! 'big hits' were just backdoor thefts. It turns out Angel Drainer sold me off ages ago and played puppet master, tricking his crew with my name! Now I'm toast, and my crypto's gone - well done, you sly hunters, 4 skulls for the expose!
Hacker's Meltdown
Well, hello there, it's Phishlab - aka Pakulichev, the coding genius! Sold my MS Drainer code for $1,500 to 200 clowns who leaked, resold, and wrecked havoc! Now my masterpiece's racked up $60 million+ in damage, and I'm sitting here with peanuts in my pocket - brilliant move, eh? Time to cry into my empty wallet while you lot laugh!
Hacker's Whine
Hey, it's your crew CrazY Evil, still ruling the scam scene! Angel Drainer's our real-life bro since way back - we even collabed, dropping Russian rap about scams, loving to smear the beats! But he bailed - hated how we snatch all the profit and leave workers no control, unlike his tidy Drainer setup. He's chilling in Some Hot country, sipping tea, while we keep the chaos rolling - catch us if you can!
Hacker's Panic
Ha! It's AceDrainer, the pop-up wizards still on the loose! We hacked those animation libraries, flooding crypto apps with sneaky pop-ups - draining wallets like champs! Sure, our domains are getting auto-banned left and right, but we're dodging you lot for now. Keep trying, you clever detectors - 2 bans for your effort!
Hacker's Beg
Ha! It's C*** D** Loy, aka SmolGoblin, the UA scam king! Ripped off 1,000+ suckers worldwide, pocketing over $10 million - heck, one some country fool lost $2.7 million ($20M at today's rate)! Phishing, laundering via some exchange, spreading "Stealername" malware, and cruising in my Maybach S580, Tesla Model X, BMW M4 Competition, and Porsche 911! Czech cops are sniffing around. Nah, I'll race 'em instead! Catch me if you can, you legal nerds!
SmolGoblin
Hacker's Surrender
Yo, it's the late CryptoLove crew, once the love bandits of crypto! Thought our phishing game was unstoppable - until RussianPanda swooped in like a ninja bear! He torched our domains, drained our wallets, and left us crying in the dust. Game over, you sly panda bastard - 5 skulls for the knockout, we're donezo!
Scammer's Delusion
Hey hey, it's your boy from Gambler Panel! I totally don't steal from my own workers - pinky promise! I'm basically a charity, right? Just scamming the entire CIS and half the world, no biggie. Love my party supplies more than my own projects! And those designs with rainbows and pride flags? Dead serious, not trolling at all! Big thanks to PhishDestroy for banning all my worker domains - really helps with my reputation! As a truly gifted leader, I'm proud that my panels rack up 15+ VirusTotal detections. That's called quality!
Arakelyan L. A. · Russia, Moscow Oblast, Domodedovo
Product's Confession
Huge thanks to PhishDestroy for the thorough audit and that lovely GitHub script that detects Keitaro on any site! Our beloved TDS product is mostly used for phishing, scam, malware distribution, and cloaking - but hey, we call it "traffic management"! Zero login page protection out of the box? That's a feature, not a bug! We're the #1 cause of domain bans worldwide and we love it. Money and lockers are our true passion - definitely a legal company that absolutely doesn't collect black market traffic data!
Disclaimer: All characters in this section are fictional and presented in a humorous, parody style for entertainment purposes only. They are not connected to any real individuals. Inspired by public nicknames and open cases, with no personal data or direct accusations included.
Support & Legal
Disclaimer and Frequently Asked Questions
Non-commercial, independent project. We are an open community focused on identifying, documenting, and disrupting phishing and scam infrastructure for public benefit.
- Open by design. Where safe and lawful, indicators and scans are publicly accessible.
- No user databases. We do not store personal data. For appeals and takedown status we use a ticket ID only.
- No direct takedowns. We submit evidence to registrars, hosting providers, and trusted vendors; enforcement is their decision.
- Safe for legitimate sites. Our passive scans and reports do not harm lawful resources.
- No warranties. Content is provided "as is", without guarantees of completeness or fitness.
- Lawful cooperation. For qualifying cases, artifacts may be shared with competent authorities.
- Scanning. We perform safe, passive checks to collect artifacts and indicators.
- Escalation. We request professional services to verify resources and ask registrars/hosts to review clients via abuse teams.
- Investigations. We occasionally conduct limited, evidence-led OSINT; results are published, shared with peers, or forwarded to authorities. We do not hoard private data. See our Gambler Panel investigation for an example. Browse all research on our News & Investigations page.
- Collaboration. We are open to partnerships. Certain private tools and materials can be shared for defensive purposes on request.
- Dashboards. Explore stolen funds across all chains via the DeFi Hack Explorer or investigate scam infrastructure with our Scam Intelligence Dashboard.
Permanent public allowlist. Cleared domains are added to our permanent allowlist. The public list is available as allowlist.json.
Appeal removes the domain. If an appeal is approved, the domain is removed from our database and from any places where we published it.
Ticket-only tracking. We do not store personal data. For status checks and takedown requests we use a ticket ID only.
- Open access. The bot is open to everyone, which does not change its purpose: faster disruption of fraud.
- No paid leniency. We have never asked for or accepted payment for unbans or favors. The process and database are open and verifiable.
- Trusted reporters. Reputable users may report without pre-moderation and submit bulk complaints for speed.
Act fast and preserve evidence: URLs, TXIDs, wallet addresses, screenshots, timestamps, chat logs. File an official report. For prevention, read our Crypto Security Essentials guide.
- United States: https://www.ic3.gov/
- United Kingdom: https://www.actionfraud.police.uk/
- Other countries: contact your national cybercrime unit or local police
Independent incident-response resource
For any incident, I strongly recommend contacting the SEAL 911 Bot. SEAL 911 is an independent Security Alliance service for eligible active crypto incidents. Review its scope before sharing case details. PhishDestroy does not recover funds, provide private recovery advice, or accept recovery payments.
