Fact-check findings
What an automated fact-checker found when it re-read Porkbun against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
11 claimsThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #2[disputed][awaiting moderator]in section: Company Background
“As of mid-2024, the company manages over 3.45 million domain names, making it the approximately 20th largest ICANN-accredited registrar globally and the 9th largest for new TLDs.”
reviewerAs of mid-2024, Porkbun managed over 3.45 million domain names, making it the ~20th largest ICANN-accredited registrar globally and 9th largest for new TLDs.The domain-count figure (3.45 million) is conflated with the mid-2024 date; the registrar's own June 2024 announcement (the cited source) reported just over 2 million domains at that time. The ranking figures (20th/9th) do correctly correspond to the mid-2024 announcement.Proposed correction (not yet applied)As of mid-2024, the company managed over 2 million domain names, making it the approximately 20th largest ICANN-accredited registrar globally and the 9th largest for new TLDs. - #4[disputed][awaiting moderator]in the summary
“including on-chain investigator ZachXBT — for hosting phishing infrastructure linked to Angel Drainer and Inferno Drainer wallet-draining services, including fake Ledger sites”
reviewerOn-chain investigator ZachXBT flagged Porkbun in connection with phishing infrastructure linked to Angel Drainer and Inferno Drainer.Extensive search found no source connecting ZachXBT specifically to Angel Drainer/Inferno Drainer phishing domains registered at Porkbun; none of the section's own cited sources are ZachXBT sources either. A real, well-documented ZachXBT-Porkbun connection exists but concerns a different incident (DNS hijack of two DEXs), which the page omits entirely.Proposed correction (not yet applied)including on-chain investigator ZachXBT, who identified Porkbun as the registrar responsible for a November 2023 DNS hijack that redirected users of the DEXs Aerodrome and Velodrome to phishing sites (with a similar attack recurring in November 2025) — for hosting phishing infrastructure linked to Angel Drainer and Inferno Drainer wallet-draining services, including fake Ledger sites - #5[disputed][awaiting moderator]in section: Flagging by ZachXBT and Crypto Security Community
“On-chain investigator ZachXBT has flagged Porkbun in the context of phishing infrastructure linked to Angel Drainer and Inferno Drainer, two prevalent drainer-as-a-service operations responsible for hundreds of millions of dollars in crypto losses.”
reviewerZachXBT has flagged Porkbun in the context of phishing infrastructure linked to Angel Drainer and Inferno Drainer; abuse reports against Ledger-impersonating domains were acted upon slowly.None of the three sources cited for this section mention ZachXBT. The specific claim that ZachXBT flagged Angel Drainer/Inferno Drainer phishing domains at Porkbun could not be corroborated anywhere, while a different, well-documented ZachXBT statement about Porkbun (DNS hijack of Aerodrome/Velodrome) was found and is omitted from the page.Proposed correction (not yet applied)On-chain investigator ZachXBT identified Porkbun as the registrar responsible for a November 2023 DNS hijack that redirected users of the DEXs Aerodrome and Velodrome to phishing sites, with over $100,000 lost and a similar attack recurring in November 2025; separately, third-party trackers link phishing infrastructure using Angel Drainer and Inferno Drainer, two prevalent drainer-as-a-service operations responsible for hundreds of millions of dollars in crypto losses, to domains registered through Porkbun. - #11[disputed][awaiting moderator]in section: Abuse Response Record and Enforcement Concerns
“According to PhishDestroy's tracking, 71% of reported domains remained active after reports were filed, with 194 domains still live and 595 taken down.”
reviewerPhishDestroy tracked 274 phishing domains registered through Porkbun via 280 abuse reports since January 2, 2026; 71% remained active (194 still live), and 595 were taken down.This is an internal consistency error independent of PhishDestroy's live figures: with 274 tracked domains and 194 reported still live, the taken-down count must be approximately 80, not 595.Proposed correction (not yet applied)According to PhishDestroy's tracking, 71% of reported domains remained active after reports were filed, with 194 domains still live and 80 taken down. - #12[disputed][awaiting moderator]in section: Abuse Response Record and Enforcement Concerns
“PhishDestroy assigns Porkbun a Global Risk Score of 25/100 (elevated)”
reviewerPhishDestroy assigns Porkbun a Global Risk Score of 25/100, which it characterizes as 'elevated.'The numeric score (25/100) is correct, but the page's 'elevated' characterization contradicts PhishDestroy's own stated risk-level label of 'moderate' / 'relatively low potential for abuse.'Proposed correction (not yet applied)PhishDestroy assigns Porkbun a Global Risk Score of 25/100 (moderate) - #13[disputed][awaiting moderator]in section: Industry Comparison and Context
“PhishDestroy's Global Risk Score of 25/100 for Porkbun indicates an elevated but not extreme posture compared to high-risk registrars like NiceNIC, which PhishDestroy notes has over 90% of domains associated with illegal content.”
reviewerPhishDestroy's Global Risk Score of 25/100 for Porkbun indicates an elevated but not extreme posture.Repeats the same mischaracterization found in the Abuse Response Record section.Proposed correction (not yet applied)PhishDestroy's Global Risk Score of 25/100 for Porkbun indicates a moderate posture compared to high-risk registrars like NiceNIC, which PhishDestroy notes has over 90% of domains associated with illegal content. - #16[disputed][awaiting moderator]in section: Abuse Response Record and Enforcement Concerns
“In contrast, Porkbun's public Twitter account responded to at least one security researcher report (from firm Coinspect, May 2025) stating it had 'pinged the abuse department' and confirmed the domain was subsequently suspended — suggesting the company does act on high-visibility reports.”
reviewerPorkbun's public Twitter account responded to a security researcher report from firm Coinspect in May 2025, stating it had 'pinged the abuse department' and the domain was suspended.The tweet content is accurate but the date is wrong; decoding the status ID places the tweet on September 8, 2025.Proposed correction (not yet applied)In contrast, Porkbun's public Twitter account responded to at least one security researcher report (from firm Coinspect, September 2025) stating it had 'pinged the abuse department' and confirmed the domain was subsequently suspended — suggesting the company does act on high-visibility reports. - #17[disputed][awaiting moderator]in the timeline
“2026-05-01”
reviewerPorkbun's Twitter response to Coinspect occurred in May 2026.Timeline entry uses a different wrong date than the section 4 prose (May 2025 vs May 2026), and both are wrong; the tweet is from September 2025.Proposed correction (not yet applied)2025-09-08 - #18[disputed][awaiting moderator]in the timeline
“2026-05”
reviewerPorkbun's Twitter response to Coinspect occurred in 2026-05.Same underlying date error as the date_original field for this timeline entry.Proposed correction (not yet applied)2025-09 - #20[disputed][awaiting moderator]in section: Angel Drainer and Inferno Drainer Context
“Angel Drainer is a phishing-as-a-service operation that emerged around early 2023 and was among the primary tools used in the December 2023 Ledger Connect Kit supply-chain exploit, which drained approximately $484,000-$610,000 from DeFi users in a two-hour window.”
reviewerAngel Drainer was among the primary tools used in the December 2023 Ledger Connect Kit exploit, which drained approximately $484,000-$610,000 from DeFi users in a two-hour window.The exploit figures and drainer-service description are confirmed, but the 'early 2023' emergence date conflicts with multiple sources dating Angel Drainer's emergence to around August 2023.Proposed correction (not yet applied)Angel Drainer is a phishing-as-a-service operation that emerged around August 2023 and was among the primary tools used in the December 2023 Ledger Connect Kit supply-chain exploit, which drained approximately $484,000-$610,000 from DeFi users in a two-hour window. - #21[disputed][awaiting moderator]in the timeline
“2023-03”
reviewerAngel Drainer phishing-as-a-service begins operations in March 2023.Same underlying date error as the sections[4] finding.Proposed correction (not yet applied)2023-08
unverifiable
3 claimsNo source the reviewer could reach confirms or contradicts the claim.
- #6[unverifiable][awaiting moderator]in section: Phishing Domain Volume and Drainer Kit Detection
“Porkbun LLC has 889 flagged phishing domains in its database as of April 2026 — representing roughly 0.026% of Porkbun's total domain portfolio”
reviewerPhishDestroy's database records 889 flagged phishing domains registered through Porkbun as of April 2026, ~0.026% of Porkbun's total domain portfolio.The 889-domain figure is plausible given the source's topical relevance but could not be independently pinned down because PhishDestroy's counts change continuously and the archived snapshot was inaccessible. - #8[unverifiable][awaiting moderator]in section: Phishing Domain Volume and Drainer Kit Detection
“A specific example domain identified by PhishDestroy as registered through Porkbun is ledgersync.app, which impersonates Ledger's sync functionality.”
reviewerledgersync.app is a PhishDestroy-identified phishing domain registered through Porkbun that impersonates Ledger's sync functionality.Plausible given the general pattern of Ledger-impersonation domains at Porkbun, but the specific domain-to-registrar pairing could not be independently confirmed. - #23[unverifiable][awaiting moderator]in section: Flagging by ZachXBT and Crypto Security Community
“Etherscan, the Ethereum block explorer, is also cited among source tags in the context of wallet addresses used by draining campaigns that leveraged Porkbun-registered domains.”
reviewerEtherscan is cited among source tags in the context of wallet addresses used by draining campaigns that leveraged Porkbun-registered domains.No etherscan.io URL appears anywhere in this section's sources or in sources_used, and no specific Etherscan tag or address could be identified to check; the claim is too vague to verify independently.
stale
1 claimThe claim was accurate when written but events since have overtaken it.
- #3[stale][awaiting moderator]in the summary
“managing over 3.45 million domains”
reviewerPorkbun currently manages over 3.45 million domains.As a standalone current-state figure the 3.45 million count is now stale; Porkbun's own August 2026 announcement puts the count above 4 million.Proposed correction (not yet applied)managing over 4 million domains
confirmed
12 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in section: Company Background
“Porkbun LLC is an ICANN-accredited domain name registrar (IANA Registrar ID 1861) founded around 2014-2015 by Ray King and Peter Brual, and based in Sherwood, Oregon, USA. The company is a wholly-owned subsidiary of Top Level Design LLC, an ICANN-accredited TLD operator also founded by Ray King.”
reviewerPorkbun LLC was founded circa 2014-2015 by Ray King and Peter Brual, based in Sherwood, Oregon, is a wholly-owned subsidiary of Top Level Design LLC, and holds IANA Registrar ID 1861.Core corporate-history facts are corroborated by multiple independent sources (ICANNWiki, Wikipedia's Top Level Design article, aggregator sites). - #7[confirmed][no action needed]in section: Phishing Domain Volume and Drainer Kit Detection
“Angel Drainer is the most prevalent (4,385 instances across all registrars), followed by Solana Drainer and WalletConnect abuse”
reviewerAngel Drainer is the most prevalent drainer kit detected on phishing domains, with 4,385 instances across all registrars.The Angel Drainer domain count matches PhishDestroy's current live figure precisely. - #9[confirmed][no action needed]in section: Phishing Domain Volume and Drainer Kit Detection
“Another example, chatdefi.app, was registered through Porkbun on April 8, 2026 and hosts a crypto drainer kit.”
reviewerchatdefi.app, registered through Porkbun on April 8, 2026, hosts a crypto drainer kit.Registration date, registrar, and drainer classification all corroborated. - #10[confirmed][no action needed]in section: Phishing Domain Volume and Drainer Kit Detection
“Porkbun does not appear in the top-20 registrars by phishing domain count in the Cybercrime Information Center's 2024-2025 annual registrar phishing report”
reviewerPorkbun does not appear in the top 20 registrars by phishing domain count in the Cybercrime Information Center's May 2024-April 2025 report, which lists NameSilo, NICENIC, Dominet, Namecheap, and GoDaddy as leading contributors.Directly confirmed against the cited report. - #14[confirmed][no action needed]in section: Abuse Response Record and Enforcement Concerns
“The platform states that 'silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision.'”
reviewerPhishDestroy states 'silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision.'Quote verified verbatim (page's version is a truncated form of the full sentence, but faithfully represents it). - #15[confirmed][no action needed]in section: Abuse Response Record and Enforcement Concerns
“In at least one documented case (chatdefi.app, April 2026), a PhishDestroy abuse report filed on the registration date received no registrar action for over one month.”
reviewerIn the chatdefi.app case, a PhishDestroy abuse report filed on the domain's registration date received no registrar action for over one month.Confirmed and, if anything, understated given how much time has actually elapsed. - #19[confirmed][no action needed]in section: Abuse Response Record and Enforcement Concerns
“Porkbun's stated abuse policy requires 'definitive and verifiable proof' for all reports, and the company restricts its scope to DNS-level abuse under ICANN contract requirements, declining to address content disputes or trademark issues.”
reviewerPorkbun's abuse policy requires 'definitive and verifiable proof' and restricts scope to DNS-level abuse, declining to address content disputes or trademark issues.Quotes verified verbatim against the official abuse policy page.citedporkbun.com/abuse - #22[confirmed][no action needed]in section: Angel Drainer and Inferno Drainer Context
“Inferno Drainer, a related drainer-as-a-service active from 2022 into 2023, stole over $82 million from more than 100,000 victims before it claimed to shut down; Angel Drainer subsequently announced it had acquired Inferno Drainer's codebase.”
reviewerInferno Drainer, active from 2022 into 2023, stole over $82 million from more than 100,000 victims before claiming to shut down; Angel Drainer subsequently announced it had acquired Inferno Drainer's codebase.Figures fall within the range reported by multiple independent outlets ($70M-$87M stolen, 100,000-137,000 victims). - #24[confirmed][no action needed]in section: Industry Comparison and Context
“PhishDestroy's Global Risk Score of 25/100 for Porkbun indicates an elevated but not extreme posture compared to high-risk registrars like NiceNIC, which PhishDestroy notes has over 90% of domains associated with illegal content.”
reviewerNiceNIC has over 90% of domains associated with illegal content, per PhishDestroy.Confirmed against PhishDestroy's own NiceNIC-specific investigation page (this specific claim about NiceNIC is accurate even though the parallel Porkbun risk-level characterization in the same sentence is not - see the separate risk-score finding).citedphishdestroy.io/ - #25[confirmed][no action needed]in the timeline
“Porkbun announces it has crossed 2 million domains under management, becoming the 20th largest ICANN registrar overall.”
reviewerPorkbun announced it crossed 2 million domains under management on June 24, 2024, becoming the 20th largest ICANN registrar overall.Directly confirmed and consistent with the finding on the mismatched 3.45 million figure elsewhere on the page. - #26[confirmed][no action needed]in the timeline
“Scam Sniffer reports on-chain data showing Inferno Drainer's fee address changed, with Inferno Drainer claiming Angel Drainer has taken over the entire project.”
reviewerOn October 18, 2024, Scam Sniffer reported Inferno Drainer's fee address changed, with Inferno Drainer claiming Angel Drainer took over the project.Consistent with independent October 2024 reporting on the Angel/Inferno relationship. - #27[confirmed][no action needed]in section: Industry Comparison and Context
“Comparable legitimate registrars such as Namecheap have faced similar criticism for hosting phishing infrastructure, and both are ICANN-accredited with comparable stated abuse policies.”
reviewerComparable legitimate registrars such as Namecheap have faced similar criticism for hosting phishing infrastructure.Reasonable, well-supported comparison.