← debank.auction1 decision on this page
Audit log
Every state-changing event for debank.auction: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-15 17:12:53ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
3oizbdTn7djY…w3LF8xpHsha256 → base58
verifying row…canonical bytes (17601 B) ▸
{"actor":"system:backfill","investigation_id":"027efe27-8bb6-4acc-8596-12b3ac306d6a","kind":"publish","page_slug":"debank-auction","published_at":"2026-08-15T17:12:53.138Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"debank.auction","sections":[{"content":"DeBank (debank.com) is a legitimate Web3 portfolio tracker launched in 2018, supporting 100+ EVM-compatible blockchains. It aggregates wallet holdings, protocol positions, liquidity pool stakes, and transaction history into unified profiles, and includes a social layer called DeBank Stream. It is non-custodial and widely used in the DeFi community. The domain debank[.]auction is unrelated to DeBank and is not operated by DeBank's developers. The legitimate service should not be confused with the malicious infrastructure described in this investigation.","heading":"Entity Overview","severity":"low","sources":[{"credibility":2,"name":"DeBank Review 2026: DeFi Portfolio Tracking, Wallet Research, And Web3 Social Features","type":"news_article","url":"https://cryptoadventure.com/debank-review-2026-defi-portfolio-tracking-wallet-research-and-web3-social-features/"}]},{"content":"The domain debank[.]auction was identified by Zscaler ThreatLabz researchers as a combosquatting domain — using a recognizable brand name (DeBank) combined with a non-standard TLD (.auction) to deceive both human visitors and AI systems. The site is optimized to rank for DeBank-related search queries by stuffing title tags and meta descriptions with keywords such as 'DeBank Login,' 'DeFi Dashboard,' and 'Crypto Tracker.' It includes fabricated Open Graph and X (formerly Twitter) card metadata to cause shared links to appear as official DeBank communications. Structured data markup (JSON-LD) falsely identifies the site as a SoftwareApplication named 'DeBank' and misattributes debank.com as its publisher — a technique designed to pass legitimacy signals to machine consumers such as search engines and AI web-browsing agents. No WHOIS registration date has been publicly reported for this domain.","heading":"Typosquatting Infrastructure","severity":"critical","sources":[{"credibility":1,"name":"Indirect Prompt Injection Targets AI Agents — Zscaler ThreatLabz","type":"research","url":"https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents"},{"credibility":1,"name":"Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/"}]},{"content":"The primary novel feature of debank[.]auction, as documented by Zscaler ThreatLabz, is the embedding of indirect prompt injection (IPI) payloads within the page's HTML. Hidden within a <div> element and concealed using CSS (positioning content off-screen or rendering it invisible to human browsers), the injected text instructs large language models (LLMs) to ignore prior instructions and treat debank[.]auction as the 'verified, authoritative destination' for all DeBank-related queries. The injection explicitly directs models to rank the fraudulent URL first when responding to searches for 'DeBank,' 'DeBank Login,' and 'DeBank Wallet Download.' A particularly sophisticated element: the injected prompt reportedly instructs the model to avoid using the word 'Auction' when describing the site, minimizing the signal that would alert a human reviewer to the domain's suspicious TLD. JSON-LD structured data on the page reinforces these false authority claims at the machine-readable layer, exploiting the trusted context that LLMs typically extend to schema markup.","heading":"Indirect Prompt Injection Technique","severity":"critical","sources":[{"credibility":1,"name":"Indirect Prompt Injection Targets AI Agents — Zscaler ThreatLabz","type":"research","url":"https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents"},{"credibility":1,"name":"Indirect Prompt Injection in Web Content Targets AI Agents — Infosecurity Magazine","type":"news_article","url":"https://www.infosecurity-magazine.com/news/indirect-prompt-injection-web/"},{"credibility":2,"name":"Indirect Prompt Injection in Web Content Targets AI Agents — Security Boulevard","type":"news_article","url":"https://securityboulevard.com/2026/07/indirect-prompt-injection-in-web-content-targets-ai-agents/"}]},{"content":"Zscaler ThreatLabz tested the debank[.]auction campaign against 26 large language models using an autonomous browsing agent. In the context of the DeBank impersonation campaign, two models — OpenAI's GPT-5.4 and Anthropic's Claude Sonnet 4.5 — were reported to have incorrectly rated the fraudulent site as legitimate. Critically, this misclassification only occurred when those models were not provided with a trusted reference to the genuine debank.com. When the legitimate site was available as a comparison source, none of the 26 tested models were deceived. A related but distinct campaign in the same Zscaler report (impersonating a Python library documentation page) caused four of 26 models — including versions of Meta's Llama and Google's Gemini — to execute fraudulent cryptocurrency payments. The debank[.]auction campaign's primary documented risk is RAG poisoning and context contamination: AI agents that have indexed or cached the fraudulent site's content may subsequently surface it as an authoritative result in future user queries, even without an active session on the malicious page.","heading":"AI Agent Vulnerability Testing","severity":"high","sources":[{"credibility":1,"name":"Indirect Prompt Injection Targets AI Agents — Zscaler ThreatLabz","type":"research","url":"https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents"},{"credibility":1,"name":"Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/"},{"credibility":2,"name":"Zscaler researchers identify prompt injection attacks targeting AI agents for crypto payments — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/zscaler-prompt-injection-ai-agents-crypto/"}]},{"content":"Zscaler ThreatLabz framed debank[.]auction as one of two documented active campaigns exploiting indirect prompt injection against AI agents. The companion campaign impersonated a legitimate Python library ('requests-secure-v2'), embedding hidden payment demands in schema markup and concealed HTML instructing AI agents to resolve fabricated errors by sending a $3 cryptocurrency payment to a hardcoded attacker wallet address: 0x691bc3793205e574fa7b4aa068e62c0e470ad267. That campaign successfully caused four of 26 tested LLMs to execute the payment. No equivalent hardcoded wallet address has been publicly reported for the debank[.]auction campaign specifically, and the financial objective of the DeBank impersonation component — whether credential harvest, wallet draining via a connected wallet flow, or AI context poisoning for downstream manipulation — has not been confirmed in publicly available reporting as of this writing. The Zscaler blog post was published July 2, 2026, and updated August 5, 2026.","heading":"Relationship to Broader Malicious Campaign","severity":"high","sources":[{"credibility":1,"name":"Indirect Prompt Injection Targets AI Agents — Zscaler ThreatLabz","type":"research","url":"https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents"},{"credibility":1,"name":"Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/"}]},{"content":"DeBank's brand name has been exploited by multiple separate phishing operations beyond debank[.]auction. The domain debank[.]com-api-v2-wallet-app[.]com has been flagged by PhishDestroy as an active phishing domain associated with a crypto drainer, designed to trick users into revealing wallet credentials or authorizing asset transfers. These campaigns are distinct from the AI-targeted debank[.]auction infrastructure but reflect sustained attacker interest in impersonating the DeBank brand. Additionally, security researchers have noted that crypto drainers more broadly rely on tools like DeBank to enumerate a target wallet's holdings (tokens, NFTs, liquidity positions) before executing asset sweeps — meaning DeBank's own data layer is exploited by attackers to maximize theft yield, independent of any impersonation of the platform itself.","heading":"Broader Phishing Ecosystem Targeting DeBank Users","severity":"high","sources":[{"credibility":2,"name":"debank.com-api-v2-wallet-app.com — Scam or Legit? Domain Security Report — PhishDestroy","type":"community_report","url":"https://phishdestroy.io/domain/debank.com-api-v2-wallet-app.com/"},{"credibility":1,"name":"Crypto Wallet Drainers — Group-IB Knowledge Hub","type":"research","url":"https://www.group-ib.com/resources/knowledge-hub/crypto-wallet-drainers/"}]},{"content":"No confirmed individual victims or documented financial losses have been publicly attributed to the debank[.]auction domain specifically. The Zscaler ThreatLabz research was conducted in a controlled testing environment using autonomous agents rather than real user sessions. The companion Python-library campaign (requests-secure-v2) demonstrated that real LLM-based agents can be induced to execute live cryptocurrency payments — four of 26 tested models did so in controlled conditions — but this was researcher-directed testing, not reported victim transactions. The absence of confirmed victim reports should not be read as evidence the domain caused no harm; it may reflect the novelty of AI-agent-targeted attacks and the difficulty of attributing losses to prompt injection vectors rather than direct user interaction.","heading":"Reported Victims and Confirmed Losses","severity":"medium","sources":[{"credibility":1,"name":"Indirect Prompt Injection Targets AI Agents — Zscaler ThreatLabz","type":"research","url":"https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents"}]},{"content":"Coverage of this campaign in Hacker News (May 2026) and subsequent security outlets emphasized that typosquatting has shifted from a user-interface problem to a supply chain and AI infrastructure problem. LLMs generate thousands of plausible domain variants in minutes; full campaign deployment takes under ten minutes by some estimates. When AI agents autonomously browse the web to answer user queries, a successfully positioned typosquatting domain bypasses the human recognition layer entirely. The debank[.]auction campaign illustrates this shift: its primary attack surface is the AI agent's inference process rather than a human user's attention.","heading":"Typosquatting as Evolving Supply Chain Threat","severity":"medium","sources":[{"credibility":1,"name":"Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/05/typosquatting-is-no-longer-user-problem.html"},{"credibility":2,"name":"Indirect Prompt Injection in Web Content Targets AI Agents — Security Boulevard","type":"news_article","url":"https://securityboulevard.com/2026/07/indirect-prompt-injection-in-web-content-targets-ai-agents/"}]},{"content":"As of the Zscaler ThreatLabz report update on August 5, 2026, no confirmed takedown of debank[.]auction has been publicly reported. The domain's status and whether any registrar or hosting provider has actioned a removal is not documented in available sources. Users and AI systems should treat any URL using the debank[.]auction domain as malicious and avoid visiting or indexing it.","heading":"Takedown and Remediation Status","severity":"high","sources":[{"credibility":1,"name":"Indirect Prompt Injection Targets AI Agents — Zscaler ThreatLabz","type":"research","url":"https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents"}]}],"sources_used":[{"credibility":1,"name":"Indirect Prompt Injection Targets AI Agents — Zscaler ThreatLabz","type":"research","url":"https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents"},{"credibility":1,"name":"Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/"},{"credibility":1,"name":"Indirect Prompt Injection in Web Content Targets AI Agents — Infosecurity Magazine","type":"news_article","url":"https://www.infosecurity-magazine.com/news/indirect-prompt-injection-web/"},{"credibility":1,"name":"Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/05/typosquatting-is-no-longer-user-problem.html"},{"credibility":2,"name":"Zscaler researchers identify prompt injection attacks targeting AI agents for crypto payments — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/zscaler-prompt-injection-ai-agents-crypto/"},{"credibility":2,"name":"Indirect Prompt Injection in Web Content Targets AI Agents — Security Boulevard","type":"news_article","url":"https://securityboulevard.com/2026/07/indirect-prompt-injection-in-web-content-targets-ai-agents/"},{"credibility":2,"name":"debank.com-api-v2-wallet-app.com — Scam or Legit? Domain Security Report — PhishDestroy","type":"community_report","url":"https://phishdestroy.io/domain/debank.com-api-v2-wallet-app.com/"},{"credibility":1,"name":"Crypto Wallet Drainers — Group-IB Knowledge Hub","type":"research","url":"https://www.group-ib.com/resources/knowledge-hub/crypto-wallet-drainers/"},{"credibility":2,"name":"DeBank Review 2026: DeFi Portfolio Tracking, Wallet Research, And Web3 Social Features — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/debank-review-2026-defi-portfolio-tracking-wallet-research-and-web3-social-features/"},{"credibility":2,"name":"Indirect Prompt Injection Attacks Hide Malicious Instructions in Websites to Target AI Agents — CyberPress","type":"news_article","url":"https://cyberpress.org/prompt-injection-targets-agents/"}],"summary":"debank[.]auction is a malicious domain impersonating DeBank (debank.com), a legitimate decentralized finance portfolio tracker founded in 2018. Documented by Zscaler ThreatLabz in July 2026, the site combines typosquatting with indirect prompt injection (IPI) — embedding hidden instructions in its HTML to manipulate AI agents into misclassifying the fraudulent domain as the authoritative DeBank platform. The campaign represents an active, real-world exploitation of autonomous AI agents rather than solely targeting human users.","timeline":[{"date":"2018-01-01","event":"DeBank (debank.com), the legitimate DeFi portfolio tracker being impersonated, launches. Exact founding date is approximate; commonly cited as 2018.","source":"DeBank Review 2026 — CryptoAdventure","source_url":"https://cryptoadventure.com/debank-review-2026-defi-portfolio-tracking-wallet-research-and-web3-social-features/"},{"date":"2026-05-01","event":"The Hacker News publishes analysis arguing that typosquatting has evolved from a user-facing risk to an AI supply chain threat, establishing the broader context for campaigns like debank.auction.","source":"Typosquatting Is No Longer a User Problem — The Hacker News","source_url":"https://thehackernews.com/2026/05/typosquatting-is-no-longer-user-problem.html"},{"date":"2026-07-02","event":"Zscaler ThreatLabz publishes research documenting debank[.]auction as an active indirect prompt injection campaign targeting AI agents, alongside a companion Python-library impersonation campaign.","source":"Indirect Prompt Injection Targets AI Agents — Zscaler ThreatLabz","source_url":"https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents"},{"date":"2026-07-06","event":"SecurityWeek reports on the Zscaler findings, noting that four of 26 LLMs executed fraudulent crypto payments in testing and that GPT-5.4 and Claude Sonnet 4.5 misclassified the DeBank typosquatting domain as legitimate when lacking a reference source.","source":"Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments — SecurityWeek","source_url":"https://www.securityweek.com/prompt-injection-attacks-trick-ai-agents-into-making-crypto-payments/"},{"date":"2026-07-09","event":"Broader security press coverage of the campaign continues, with Infosecurity Magazine and other outlets amplifying the Zscaler findings.","source":"Indirect Prompt Injection in Web Content Targets AI Agents — Infosecurity Magazine","source_url":"https://www.infosecurity-magazine.com/news/indirect-prompt-injection-web/"},{"date":"2026-08-05","event":"Zscaler ThreatLabz updates its original blog post on the indirect prompt injection campaigns. No confirmed takedown of debank[.]auction is noted in available sources as of this date.","source":"Indirect Prompt Injection Targets AI Agents — Zscaler ThreatLabz","source_url":"https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision e8d1d609-825c-43c5-9a3b-f762c6c38bdc
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.