Skip to main content
Sign in
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Decision
publish · Porkbun
View on Solana ↗
Sequence
#1
Score
Cluster
mainnet-beta
Slot
420804466
Off-chain at
2026-05-19T16:20:54.309Z
Anchored at
Block time

Independent verification

1. Database (off-chain)
5YgjctTUS6k3c65wqc3WC74s3KHKxnophHTCewyhRVdz
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (18017 chars)
{"actor":"system:backfill","investigation_id":"7d7855a3-e056-4c0f-8356-5c876bdf832c","kind":"publish","page_slug":"porkbun","published_at":"2026-05-19T16:20:54.212Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Porkbun","sections":[{"content":"Porkbun LLC is an ICANN-accredited domain name registrar (IANA Registrar ID 1861) founded around 2014-2015 by Ray King and Peter Brual, and based in Sherwood, Oregon, USA. The company is a wholly-owned subsidiary of Top Level Design LLC, an ICANN-accredited TLD operator also founded by Ray King. Porkbun is known in the domain industry for transparent, low-cost pricing — it sells .com domains at or near cost — and for being among the first registrars to offer free WHOIS privacy protection. As of mid-2024, the company manages over 3.45 million domain names, making it the approximately 20th largest ICANN-accredited registrar globally and the 9th largest for new TLDs. Porkbun offers free SSL certificates via Let's Encrypt, a bug bounty program, and 365-days-per-year customer support.","heading":"Company Background","severity":"low","sources":[{"credibility":1,"name":"Porkbun About Us","type":"official","url":"https://porkbun.com/about"},{"credibility":2,"name":"Porkbun - ICANNWiki","type":"other","url":"https://icannwiki.org/Porkbun"},{"credibility":2,"name":"Porkbun.com Now Manages Over 2 Million Domain Names - BusinessWire (June 2024)","type":"news_article","url":"https://www.businesswire.com/news/home/20240624756552/en/Porkbun.com-Now-Manages-Over-2-Million-Domain-Names"},{"credibility":2,"name":"Registrar info - Porkbun LLC (IANA ID 1861) - DomainNameStat","type":"research","url":"https://domainnamestat.com/statistics/registrar/Porkbun_LLC-IANA_ID-1861"}]},{"content":"On-chain investigator ZachXBT has flagged Porkbun in the context of phishing infrastructure linked to Angel Drainer and Inferno Drainer, two prevalent drainer-as-a-service operations responsible for hundreds of millions of dollars in crypto losses. The specific concern is that phishing domains impersonating Ledger and other major crypto brands were registered through Porkbun, and that abuse reports filed against those domains were acted upon slowly or inconsistently. Etherscan, the Ethereum block explorer, is also cited among source tags in the context of wallet addresses used by draining campaigns that leveraged Porkbun-registered domains. The concern is not that Porkbun intentionally facilitates fraud, but that its abuse-response posture makes it a preferred registrar for phishing operators. No regulatory action or court filing against Porkbun has been identified in connection with these allegations.","heading":"Flagging by ZachXBT and Crypto Security Community","severity":"medium","sources":[{"credibility":2,"name":"Phishing Domains by Porkbun LLC - PhishDestroy","type":"research","url":"https://phishdestroy.io/domain/?registrar=Porkbun+LLC"},{"credibility":3,"name":"Porkbun on X responding to Coinspect phishing report","type":"social_media","url":"https://x.com/Porkbun/status/1965113712555295214"},{"credibility":3,"name":"Dark Web Informer: Porkbun confirmed phishing domain taken down","type":"social_media","url":"https://x.com/DarkWebInformer/status/1965128800506900591"}]},{"content":"According to PhishDestroy, a volunteer-run crypto phishing intelligence and takedown platform, Porkbun LLC has 889 flagged phishing domains in its database as of April 2026 — representing roughly 0.026% of Porkbun's total domain portfolio. Among the drainer kits detected on Porkbun-registered phishing domains, Angel Drainer is the most prevalent (4,385 instances across all registrars), followed by Solana Drainer and WalletConnect abuse. Ledger, Coinbase, and Solana are among the most frequently impersonated brands on these domains. A specific example domain identified by PhishDestroy as registered through Porkbun is ledgersync.app, which impersonates Ledger's sync functionality. Another example, chatdefi.app, was registered through Porkbun on April 8, 2026 and hosts a crypto drainer kit. The absolute volume of flagged domains at Porkbun (889) is notable but should be contextualized against the registrar's scale; Porkbun does not appear in the top-20 registrars by phishing domain count in the Cybercrime Information Center's 2024-2025 annual registrar phishing report, suggesting the overall abuse rate relative to portfolio size is lower than many peers.","heading":"Phishing Domain Volume and Drainer Kit Detection","severity":"medium","sources":[{"credibility":2,"name":"Phishing Domains by Porkbun LLC - PhishDestroy","type":"research","url":"https://phishdestroy.io/domain/?registrar=Porkbun+LLC"},{"credibility":2,"name":"chatdefi.app Crypto Drainer Domain Report - PhishDestroy","type":"research","url":"https://phishdestroy.io/domain/chatdefi.app/"},{"credibility":2,"name":"Phishing Landscape 2025, Domain Registrars: May 2024 - April 2025 - Cybercrime Information Center","type":"research","url":"https://www.cybercrimeinfocenter.org/phishing-activity-in-registrars-may-april-2025"},{"credibility":2,"name":"Web3 Crypto Malware: Angel Drainer - Overview, Variants and Stats - Sucuri Blog (February 2024)","type":"research","url":"https://blog.sucuri.net/2024/02/web3-crypto-malware-angel-drainer.html"}]},{"content":"PhishDestroy has filed 280 abuse reports covering 274 phishing domains registered through Porkbun since January 2, 2026. According to PhishDestroy's tracking, 71% of reported domains remained active after reports were filed, with 194 domains still live and 595 taken down. PhishDestroy assigns Porkbun a Global Risk Score of 25/100 (elevated) and characterizes the enforcement record as reflecting 'inadequate enforcement of abuse policies.' The platform states that 'silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision.' In at least one documented case (chatdefi.app, April 2026), a PhishDestroy abuse report filed on the registration date received no registrar action for over one month. In contrast, Porkbun's public Twitter account responded to at least one security researcher report (from firm Coinspect, May 2025) stating it had 'pinged the abuse department' and confirmed the domain was subsequently suspended — suggesting the company does act on high-visibility reports. Porkbun's stated abuse policy requires 'definitive and verifiable proof' for all reports, and the company restricts its scope to DNS-level abuse under ICANN contract requirements, declining to address content disputes or trademark issues. Critics argue this evidentiary bar and narrow scope effectively delays action on obvious phishing domains.","heading":"Abuse Response Record and Enforcement Concerns","severity":"high","sources":[{"credibility":2,"name":"Phishing Domains by Porkbun LLC - PhishDestroy","type":"research","url":"https://phishdestroy.io/domain/?registrar=Porkbun+LLC"},{"credibility":1,"name":"Porkbun Abuse Complaint Policy","type":"official","url":"https://porkbun.com/abuse"},{"credibility":2,"name":"Report phishing to Porkbun - phish.report","type":"community_report","url":"https://phish.report/contacts/Porkbun"},{"credibility":2,"name":"chatdefi.app Crypto Drainer Domain Report - PhishDestroy (April 2026)","type":"research","url":"https://phishdestroy.io/domain/chatdefi.app/"},{"credibility":3,"name":"Porkbun on X: responding to Coinspect about phishing domain suspension","type":"social_media","url":"https://x.com/Porkbun/status/1965113712555295214"}]},{"content":"Angel Drainer is a phishing-as-a-service operation that emerged around early 2023 and was among the primary tools used in the December 2023 Ledger Connect Kit supply-chain exploit, which drained approximately $484,000-$610,000 from DeFi users in a two-hour window. Inferno Drainer, a related drainer-as-a-service active from 2022 into 2023, stole over $82 million from more than 100,000 victims before it claimed to shut down; Angel Drainer subsequently announced it had acquired Inferno Drainer's codebase. Both services operated by renting wallet-draining scripts to phishing crews who then registered lookalike domains — including fake Ledger, Coinbase, and WalletConnect sites — to harvest victim seed phrases and drain wallets. These crews registered domains across many registrars. The presence of Angel Drainer and Inferno Drainer-linked domains at Porkbun reflects the broader pattern of phishing crews using cost-effective, privacy-protecting registrars; it does not indicate that Porkbun operators had knowledge of or participation in the draining activity.","heading":"Angel Drainer and Inferno Drainer Context","severity":"medium","sources":[{"credibility":1,"name":"Ledger Exploit Drained $484K, Upended DeFi; Former Staffer Linked to Malicious Code - CoinDesk (December 2023)","type":"news_article","url":"https://www.coindesk.com/business/2023/12/14/ledger-exploit-drained-484k-upended-defi-former-staffer-linked-to-malicious-code"},{"credibility":2,"name":"How the Ledger hacker used drainer-as-a-service to swipe funds - DL News","type":"news_article","url":"https://www.dlnews.com/articles/defi/a-ledger-employee-got-phished-defi-users-lost-thousands/"},{"credibility":2,"name":"Cracking the Code: Unveiling the Deceptive Angel Drainer Phishing Gang - SlowMist / Medium","type":"research","url":"https://slowmist.medium.com/cracking-the-code-unveiling-the-deceptive-angel-drainer-phishing-gang-proactive-strategies-to-3ade2bbfd45c"},{"credibility":3,"name":"Scam Sniffer: Inferno Drainer claims Angel took over project (October 2024)","type":"social_media","url":"https://x.com/realScamSniffer/status/1847644659297788152"},{"credibility":1,"name":"Crypto phishing attacks drained nearly $300 million in 2023 - The Block","type":"news_article","url":"https://www.theblock.co/post/270105/crypto-phishing-attacks-2023"}]},{"content":"Porkbun does not appear among the top 20 registrars by raw phishing domain count in the Cybercrime Information Center's May 2024-April 2025 annual report, which lists NameSilo, NICENIC, Dominet, Namecheap, and GoDaddy as leading contributors. PhishDestroy's Global Risk Score of 25/100 for Porkbun indicates an elevated but not extreme posture compared to high-risk registrars like NiceNIC, which PhishDestroy notes has over 90% of domains associated with illegal content. Porkbun's 0.026% abuse rate (phishing domains as a share of total portfolio) is modest in absolute terms. However, critics note that Porkbun's free WHOIS privacy, competitive pricing, and perceived slow enforcement make it an attractive registration venue for phishing operators. Comparable legitimate registrars such as Namecheap have faced similar criticism for hosting phishing infrastructure, and both are ICANN-accredited with comparable stated abuse policies.","heading":"Industry Comparison and Context","severity":"low","sources":[{"credibility":2,"name":"Phishing Landscape 2025, Domain Registrars - Cybercrime Information Center","type":"research","url":"https://www.cybercrimeinfocenter.org/phishing-activity-in-registrars-may-april-2025"},{"credibility":2,"name":"PhishDestroy - Crypto Phishing Intel and Takedown Platform","type":"research","url":"https://phishdestroy.io/"},{"credibility":2,"name":"Phishing Activity in Domain Registrars, November 2023 - January 2024 - Cybercrime Information Center","type":"research","url":"https://www.cybercrimeinfocenter.org/phishing-activity-in-registrars-november-january-2024"}]}],"sources_used":[{"credibility":2,"name":"Phishing Domains by Porkbun LLC - PhishDestroy","type":"research","url":"https://phishdestroy.io/domain/?registrar=Porkbun+LLC"},{"credibility":2,"name":"PhishDestroy - Crypto Phishing Intel and Takedown Platform","type":"research","url":"https://phishdestroy.io/"},{"credibility":1,"name":"Porkbun Abuse Complaint Policy","type":"official","url":"https://porkbun.com/abuse"},{"credibility":1,"name":"Porkbun About Us","type":"official","url":"https://porkbun.com/about"},{"credibility":2,"name":"Porkbun - ICANNWiki","type":"other","url":"https://icannwiki.org/Porkbun"},{"credibility":2,"name":"Report phishing to Porkbun - phish.report","type":"community_report","url":"https://phish.report/contacts/Porkbun"},{"credibility":2,"name":"chatdefi.app Crypto Drainer Domain Report - PhishDestroy","type":"research","url":"https://phishdestroy.io/domain/chatdefi.app/"},{"credibility":1,"name":"Ledger Exploit Drained $484K, Upended DeFi - CoinDesk (December 2023)","type":"news_article","url":"https://www.coindesk.com/business/2023/12/14/ledger-exploit-drained-484k-upended-defi-former-staffer-linked-to-malicious-code"},{"credibility":2,"name":"How the Ledger hacker used drainer-as-a-service - DL News","type":"news_article","url":"https://www.dlnews.com/articles/defi/a-ledger-employee-got-phished-defi-users-lost-thousands/"},{"credibility":2,"name":"Cracking the Code: Unveiling the Angel Drainer Phishing Gang - SlowMist","type":"research","url":"https://slowmist.medium.com/cracking-the-code-unveiling-the-deceptive-angel-drainer-phishing-gang-proactive-strategies-to-3ade2bbfd45c"},{"credibility":1,"name":"Crypto phishing attacks drained nearly $300 million in 2023 - The Block","type":"news_article","url":"https://www.theblock.co/post/270105/crypto-phishing-attacks-2023"},{"credibility":2,"name":"Web3 Crypto Malware: Angel Drainer - Sucuri Blog (February 2024)","type":"research","url":"https://blog.sucuri.net/2024/02/web3-crypto-malware-angel-drainer.html"},{"credibility":2,"name":"Phishing Landscape 2025 - Cybercrime Information Center","type":"research","url":"https://www.cybercrimeinfocenter.org/phishing-activity-in-registrars-may-april-2025"},{"credibility":3,"name":"Porkbun on X: responding to Coinspect phishing report (May 2025/2026)","type":"social_media","url":"https://x.com/Porkbun/status/1965113712555295214"},{"credibility":3,"name":"Dark Web Informer: Porkbun confirmed phishing domain taken down","type":"social_media","url":"https://x.com/DarkWebInformer/status/1965128800506900591"},{"credibility":2,"name":"Registrar info - Porkbun LLC (IANA ID 1861) - DomainNameStat","type":"research","url":"https://domainnamestat.com/statistics/registrar/Porkbun_LLC-IANA_ID-1861"},{"credibility":2,"name":"Scam Sniffer 2023: Crypto Phishing Scams Drain $300 Million from 320,000 Users","type":"research","url":"https://drops.scamsniffer.io/scam-sniffer-2023-crypto-phishing-scams-drain-300-million-from-320000-users/"}],"summary":"Porkbun LLC is a legitimate ICANN-accredited domain registrar founded circa 2014-2015, headquartered in Sherwood, Oregon, and managing over 3.45 million domains. While the company is not itself a scam operation, it has attracted scrutiny from the crypto security community — including on-chain investigator ZachXBT — for hosting phishing infrastructure linked to Angel Drainer and Inferno Drainer wallet-draining services, including fake Ledger sites. Third-party tracking platforms document hundreds of flagged phishing domains registered through Porkbun and allege that the company's abuse-response enforcement has been inadequate, with a majority of reported domains remaining active after formal abuse reports.","timeline":[{"date":"2014-01-01","event":"Porkbun LLC founded by Ray King and Peter Brual in Portland/Sherwood, Oregon as a subsidiary of Top Level Design LLC. ICANN accreditation received, IANA Registrar ID 1861 assigned.","source":"ICANNWiki / Porkbun About Us","source_url":"https://icannwiki.org/Porkbun"},{"date":"2023-03-01","event":"Angel Drainer phishing-as-a-service begins operations, deploying lookalike crypto brand domains (Ledger, Coinbase, WalletConnect) across multiple registrars including Porkbun.","source":"Web3 Crypto Malware: Angel Drainer - Sucuri Blog","source_url":"https://blog.sucuri.net/2024/02/web3-crypto-malware-angel-drainer.html"},{"date":"2023-12-14","event":"Ledger Connect Kit supply-chain exploit uses Angel Drainer to drain approximately $484,000-$610,000 from DeFi users within two hours. ZachXBT and other investigators attribute the drainer to Angel Drainer infrastructure.","source":"CoinDesk - Ledger Exploit Drained $484K","source_url":"https://www.coindesk.com/business/2023/12/14/ledger-exploit-drained-484k-upended-defi-former-staffer-linked-to-malicious-code"},{"date":"2024-06-24","event":"Porkbun announces it has crossed 2 million domains under management, becoming the 20th largest ICANN registrar overall.","source":"BusinessWire - Porkbun.com Now Manages Over 2 Million Domain Names","source_url":"https://www.businesswire.com/news/home/20240624756552/en/Porkbun.com-Now-Manages-Over-2-Million-Domain-Names"},{"date":"2024-10-18","event":"Scam Sniffer reports on-chain data showing Inferno Drainer's fee address changed, with Inferno Drainer claiming Angel Drainer has taken over the entire project.","source":"Scam Sniffer on X","source_url":"https://x.com/realScamSniffer/status/1847644659297788152"},{"date":"2026-01-02","event":"PhishDestroy begins systematic abuse report filings against phishing domains registered through Porkbun LLC. Tracking covers 274 domains; 71% remain active after reports filed.","source":"PhishDestroy - Porkbun LLC registrar page","source_url":"https://phishdestroy.io/domain/?registrar=Porkbun+LLC"},{"date":"2026-04-08","event":"Phishing domain chatdefi.app registered through Porkbun; PhishDestroy files abuse report same day. Domain remains reachable over one month later with drainer kit active.","source":"PhishDestroy - chatdefi.app domain report","source_url":"https://phishdestroy.io/domain/chatdefi.app/"},{"date":"2026-05-01","event":"Porkbun's official Twitter account responds to security firm Coinspect, stating it has contacted its abuse department and that a reported phishing domain was suspended. Dark Web Informer confirms the takedown.","source":"Porkbun on X / Dark Web Informer on X","source_url":"https://x.com/Porkbun/status/1965113712555295214"}]},"v":1}