Fact-check findings
What an automated fact-checker found when it re-read Phantom Wallet against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
4 claimsThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #3[disputed][awaiting moderator]in the timeline
“Phantom browser extension reaches 1 million downloads”
reviewerPhantom browser extension reaches 1 million downloads (November 2021)The cited source (The Block) does not contain this claim at all, and the actual contemporaneous reporting describes 1 million active users, a different metric than 'downloads.'Proposed correction (not yet applied)Phantom reaches 1 million active users - #4[disputed][awaiting moderator]in the timeline
“https://www.theblock.co/learn/305135/what-is-the-phantom-wallet”
reviewerSource attribution for the 1 million downloads/users milestoneThe Block URL cited for this timeline entry does not discuss this milestone; CryptoSlate's November 2021 article is the actual source for the 1-million-user figure.Proposed correction (not yet applied)https://cryptoslate.com/solanas-native-wallet-phantom-just-hit-over-1-million-active-users/ - #14[disputed][awaiting moderator]in section: Phantom Chat Feature and Address Poisoning Concerns (2026)
“In December 2024, threat actors compromised the Solana web3.js npm library (versions 1.95.6 and 1.96.7) by targeting a Solana npm organization member via spear-phishing, allowing the injection of backdoor code that requested and exfiltrated private keys.”
reviewerDecember 2024 Solana web3.js npm supply chain attack involved compromised versions 1.95.6 and 1.96.7, live ~5 hours on Dec 2, 2024; Phantom and Coinbase confirmed unaffected; losses $130K-$160KThe overwhelming majority of independent, credible reporting (Hacker News, Infosecurity Magazine, SecurityWeek, Socket.dev, Wiz, and others) identifies the second compromised version as 1.95.7, not 1.96.7. The page appears to have inherited a typo from one of its four cited sources (Mitrade) rather than the more reliable ones cited alongside it. Coinbase/Phantom confirmation and the loss estimate are independently corroborated and correct.Proposed correction (not yet applied)In December 2024, threat actors compromised the Solana web3.js npm library (versions 1.95.6 and 1.95.7) by targeting a Solana npm organization member via spear-phishing, allowing the injection of backdoor code that requested and exfiltrated private keys. - #16[disputed][awaiting moderator]in the timeline
“CFTC Division of Enforcement issues Staff Letter 26-09 — a no-action position — to Phantom Technologies, permitting wallet integration with regulated derivatives platforms without introducing broker registration, subject to ten conditions”
reviewerCFTC Division of Enforcement issued Staff Letter 26-09 to Phantom TechnologiesThis timeline entry contradicts both the cited CFTC press release and the page's own Regulatory Posture section, which correctly identifies the Market Participants Division. This is an internal inconsistency and factual error.Proposed correction (not yet applied)CFTC's Market Participants Division issues Staff Letter 26-09 — a no-action position — to Phantom Technologies, permitting wallet integration with regulated derivatives platforms without introducing broker registration, subject to ten conditions
unverifiable
2 claimsNo source the reviewer could reach confirms or contradicts the claim.
- #2[unverifiable][awaiting moderator]in section: Company Background and Team
“As of early 2026, Phantom employs approximately 361 people.”
reviewerAs of early 2026, Phantom employs approximately 361 peopleNo source is cited in the section for this specific figure, and third-party headcount trackers disagree with each other (150-375 range), so the 361 figure cannot be confirmed or refuted with confidence. - #17[unverifiable][awaiting moderator]in section: April 2026 Service Outage
“The company's terms of service state it is not a money transmitter, is not subject to Bank Secrecy Act anti-money laundering requirements as a money services business, and has not been reviewed or approved by any financial regulatory authority.”
reviewerPhantom terms of service state it is not a money transmitter, is not subject to BSA/AML requirements as an MSB, and has not been reviewed/approved by any financial regulatorCould not independently re-fetch and parse the specific disclaimer language of the live phantom.com/terms page within this review; this is a plausible standard disclaimer for a self-custody wallet but was not directly re-verified against the cited primary source text.citedphantom.com/terms
stale
1 claimThe claim was accurate when written but events since have overtaken it.
- #8[stale][awaiting moderator]in section: Security Posture: Audits and Bug Bounty
“Phantom also runs a public bug bounty program hosted on Bugcrowd, covering the browser extension, mobile apps, and web services, with rewards up to $50,000 for critical vulnerabilities that could result in user fund loss.”
reviewerPhantom runs a public bug bounty program hosted on Bugcrowd, covering browser extension, mobile apps, and web services, rewards up to $50,000The $50,000 max-reward figure is confirmed, but Phantom's bug bounty is currently hosted on Cantina, not Bugcrowd; this appears to reflect an earlier program configuration that has since changed.Proposed correction (not yet applied)Phantom also runs a public bug bounty program hosted on Cantina, covering the browser extension, mobile apps, and web services, with rewards up to $50,000 for critical vulnerabilities that could result in user fund loss.
link rot
1 claimA cited source no longer resolves or no longer says what the page attributes to it.
- #18[link rot][awaiting moderator]in the cited sources
“https://web.archive.org/web/20260505063157/https://techcrunch.com/2026/04/30/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites/”
reviewerArchived (wayback) copy of the TechCrunch August 2022 Solana wallet hack articleThe live source URL itself is fine, but the stored wayback_url archive record is mismatched to a completely unrelated 2026 article, which would mislead anyone checking the archive copy.Proposed correction (not yet applied)https://web.archive.org/web/20260505063147/https://techcrunch.com/2022/08/03/solana-wallet-hack/
partially supported
2 claimsThe cited evidence supports part of the claim but not all of it.
- #12[partially supported][awaiting moderator]in section: Phishing, Fake Impersonators, and User-Facing Scams
“A fake Phantom wallet application that appeared in the Apple iOS App Store (reported June 2024), signed with a valid Apple developer certificate, which harvested seed phrases by presenting an 'import wallet' interface”
reviewerFake Phantom wallet app in Apple App Store (reported June 2024) was signed with a valid Apple developer certificate and harvested seed phrases via an 'import wallet' interfaceThe core fact (a fake app appeared in the App Store and drained funds) is confirmed, but both cited sources are less certain or silent on the 'valid Apple developer certificate' and 'import wallet interface' specifics the page states as settled fact. - #15[partially supported][awaiting moderator]in section: April 2026 Service Outage
“On March 17, 2026, the CFTC's Market Participants Division issued Staff Letter 26-09, a no-action position addressed directly to Phantom Technologies, stating it would not recommend enforcement action for failure to register as an introducing broker, provided Phantom adheres to ten specified conditions.”
reviewerCFTC's Market Participants Division issued Staff Letter 26-09 on March 17, 2026, a no-action position for Phantom subject to ten specified conditionsThe core facts (division, date, letter number, no-action nature) are confirmed. The 'ten specified conditions' figure could not be independently confirmed; secondary legal-analysis sources count the conditions differently (3 broad categories in one summary, 8-9 discrete items in another), so the precise count of 'ten' is unverified rather than clearly wrong.
confirmed
11 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in section: Company Background and Team
“Phantom Technologies, Inc. was founded in January 2021 by three former engineers from the 0x Protocol project: Brandon Millman (CEO), Francesco Agosti (CTO), and Chris Kalani.”
reviewerPhantom Technologies was founded January 2021 by Brandon Millman (CEO), Francesco Agosti (CTO), and Chris Kalani, all former 0x Protocol engineersFounder identities, roles, and founding date are consistently corroborated across multiple sources. Note the page lists Kalani without a title, while other sources identify him as CPO/co-founder, but this is not a factual error, merely an omission. - #5[confirmed][no action needed]in section: Funding and Investors
“Phantom has raised capital across three funding rounds totalling approximately $268 million.”
reviewerPhantom raised $9M Series A (2021), $109M Series B at $1.2B valuation (Jan 2022), and $150M Series C at $3B valuation (Jan 2025), totalling ~$268MAll three funding rounds' amounts, leads, and valuations are corroborated by primary and independent sources; $9M+$109M+$150M sums to $268M as stated. - #6[confirmed][no action needed]in section: Company Background and Team
“As of January 2025, Phantom reported 15 million monthly active users, 3.8 million registered usernames, $25 billion in self-custodied assets, and over 850 million on-chain transactions processed.”
reviewerPhantom reported 15M MAU, 3.8M registered usernames, $25B self-custodied assets, 850M+ on-chain transactions as of January 2025Directly verified against the primary source. - #7[confirmed][no action needed]in section: Security Posture: Audits and Bug Bounty
“That audit found no cross-site scripting vulnerabilities and no known exploitable issues in the reviewed code, but did identify two deficiencies: the absence of a BIP32 key-derivation validity check (since resolved) and a password derivation configuration that did not conform to best practices; Phantom addressed both findings by adding scrypt and the appropriate validation checks.”
reviewerLeast Authority's June 2024 audit found no XSS/known exploitable issues but identified a missing BIP32 validity check and a non-best-practice password derivation configuration, both later resolved with scryptCore technical findings are corroborated, though full PDF text could not be perfectly extracted for a word-for-word check. - #9[confirmed][no action needed]in section: Security Incidents: Demonic Vulnerability (2021–2022)
“In late September 2021, blockchain security firm Halborn privately disclosed a critical vulnerability, later publicly named 'Demonic,' to Phantom and other browser-extension wallets.”
reviewerHalborn privately disclosed the 'Demonic' vulnerability to Phantom (late Sept 2021); Phantom deployed patches Jan-Apr 2022; no exploits publicly reportedWell documented, multi-sourced, matches page description including patch timeline. - #10[confirmed][no action needed]in section: Security Incidents: August 2022 Solana Ecosystem Exploit
“On August 2-3, 2022, approximately 8,000 Solana-ecosystem wallets were drained of an estimated $5-7 million in SOL and SPL tokens.”
reviewerAugust 2022: ~8,000 Solana wallets drained ($5-7M) due to Slope Wallet's insecure key handling; Phantom-native wallets not directly affectedConsistent with contemporaneous reporting; the root-cause attribution to Slope Wallet and Phantom's non-involvement are well corroborated. - #11[confirmed][no action needed]in section: Active Civil Lawsuit: $3.1M Private Key Storage Claim (2025)
“On April 14, 2025, a group of plaintiffs led by attorney Thomas Liam Murphy filed suit against Phantom Technologies, Inc. and OKX in the U.S. District Court for the Southern District of New York.”
reviewerMurphy v. Phantom Technologies/OKX filed April 14, 2025 in SDNY; alleges Jan 20, 2025 hack of Murphy's wallets via unencrypted browser memory, $500K WIENER liquidation causing 99% collapse; damages sought at least $3.1 million; 13 co-plaintiffsDamages figure, plaintiff count, venue, and filing date all check out against the underlying complaint and secondary reporting. - #13[confirmed][no action needed]in section: December 2024 Solana Supply Chain Attack
“A user was reported to have lost approximately 3.5 WBTC (valued at roughly $150,000–$264,000) via address poisoning in a separate incident cited alongside these concerns.”
reviewerPhantom Chat concerns and 3.5 WBTC ($150,000-$264,000) address-poisoning loss cited as a separate incident; ZachXBT publicly warned about compounding social engineering riskThe page accurately reconciles a genuine discrepancy in independent reporting ($150K vs $264K valuations for the same 3.5 WBTC loss) rather than picking one figure, and correctly characterizes the loss as a separate incident cited alongside, not caused by, Phantom Chat. - #19[confirmed][no action needed]in section: Regulatory Posture
“On approximately April 7, 2026, Phantom experienced a temporary service outage that caused incorrect token balances and prices to display within the wallet interface.”
reviewerPhantom experienced a service outage on ~April 7, 2026 causing incorrect balances/prices during a token airdrop; funds unaffected; restored same day; no reimbursementConsistent with multiple independent contemporaneous reports. - #20[confirmed][no action needed]in section: Phishing, Fake Impersonators, and User-Facing Scams
“Phantom has published an open-source blocklist of over 2,000 malicious domains, integrated scam-detection warnings into the wallet UI, added an NFT-burn feature to remove spam tokens, and published detailed user education content.”
reviewerPhantom's open-source blocklist covers over 2,000 malicious domains; anti-spoofing/Lighthouse Guard Instructions feature described as first wallet to implement thisIndependently corroborated by Phantom's own security blog and the public GitHub repository. - #21[confirmed][no action needed]in section: April 2026 Service Outage
“On June 17, 2025, Phantom submitted a letter to the SEC's Crypto Task Force arguing that its self-custody wallet interface does not constitute broker activity under Section 15(a) of the Exchange Act and does not require SEC registration.”
reviewerPhantom submitted a letter to SEC Crypto Task Force on June 17, 2025 arguing it is not a broker under Section 15(a); supported Project OpenDirectly verified against the SEC.gov primary source.