Keys Defender avatar

Looking for info about domains marked as phishing

keys-defender

Published: 02 Mar 2025 › Updated: 02 Mar 2025Looking for info about domains marked as phishing

Looking for info about domains marked as phishing

image.png

image.png

AI image generated by the Karina bot in the Crypto Shots Discord


I'm looking into an issue for which 2 legit domains are falsely being flagged as phishing:

 
The issue with hivedebit was brought to my attention by eddiespino@eddiespino on behalf of starkerz@starkerz. While investigating, I saw a similar problem with v4v.app. And here we are.


HIVEDEBIT.COM

4C366BC2-E867-422B-8867-1DAD7CAC8070.jpg


V4V.APP

BD223FD2-1AF7-4488-A04D-D4838E1A4AF0.jpg


MORE CONTEXT

 
These are the bot public commands currently supported:

image.png


Who can blacklist a user or domain with the commands above:

  • Top-40 witnesses
  • 3 different users with reputation over 50 reporting the same user/domain
  • (Myself)

           

image.png

Every time someone reports anything with the commands above, it also triggers a notification in this project's Discord.


I searched in my Discord history and there are no reports for these 2 domains.
I only see notifications of these 2 domains (wrongly) marked as phishing:


- 5 memo notifications: 3 in late 2024 and 2 in January
cc: brianoflondon@brianoflondon

image.png


- 12 memo notifications that started 5 days ago

 
The transactions were sent by jthomasewsky@jthomasewsky
 

image.png


  • Did someone maliciously use the on-chain command and quickly delete their comment to prevent my automated reply to go out?   [ it can easily be verified, and it would not stop the Discord notification ]
  • Did the notifications in Discord fail for some reason, and I should dig into the code to find a bug?   [ it always worked though - PS. I just did a test and this seems fine ]

 
The only other explanation is that these domains were added for some reason (by mistake or legit reasons) in other blacklists that this bot consumes:

1. spaminator@spaminator's blacklists:

logic@logic guiltyparties@guiltyparties any clue?

2. My own lists stored on Hive: @keys-defender/phishing-db
( These lists are periodically migrated to my own database as required )

But only I have access to the latter. And these 2 flagged domains are not (and never were) there.


If the issue is not identified shortly, I'll add those domains to a whitelist to prevent more automated memos from going out incorrectly.


UPDATE 1

The issue seems to not be there anymore for v4v.app. It's still there for hivedebit.com so it should be easy for me to to find out where it's coming from.

image.png


UPDATE 2

It looks like it was just an innocent bug 🐛 - HiveDebit.com partially matched with another blacklisted domain.
For v4v.app instead, it's not currently being flagged as phishing but I would like to understand why it was. Waiting for some answers from the maintainers of the blacklists this bot consumes.
My thinking is that v4v might have been temporarily marked as compromised during the recent hack.


Appreciate the work I do? (that never received any sort of funding)         VOTE for my witness

image.png

Leave Looking for info about domains marked as phishing to:

Written by

Blockchain Scanner. Service offered by @cryptoshots.nft, WEB3 Shooter Game on Hive.

Read more #security posts


Best Posts From Keys Defender

We have not curated any of keys-defender's posts yet. But you can encourage our curation team to review posts by visiting them regularly and by referring other readers. Because we give priority to frequently read content.

More Posts From Keys Defender