Git Product home page Git Product logo

blocklist's People

Contributors

0xgumby avatar 0xstendhal avatar 4akers21 avatar adamdelphantom avatar alwaysbcoding avatar amriunix avatar anishshandilya avatar b12e avatar bfriel avatar bin-umar avatar chriskalani avatar cryptoloutre avatar dpazdan avatar gratefulamadeus avatar harii94 avatar jterry1 avatar lekkerelou avatar lfernandezpt avatar m30m avatar mcintyre94 avatar mestirman avatar njok2 avatar phantomdon avatar ryanhenifin avatar ryanhirsch-phantom avatar sadbhabie avatar shamile7335 avatar t-proctor avatar vidorge avatar whalewhite avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

blocklist's Issues

[Legitimate Site Blocked] usdcswap.com

Our website usdcswap.com was flagged as potentially deceptive here.
The website is owned and managed by Ultra Stellar and is linked to at the company website ultrastellar.com
This is a legitimate website however the USDC swap tool has been temporarily disabled some time ago. We are planning on resuming the operations over the next few months.
Please remove usdcswap.com from this blocklist as soon as possible. Metamask issue link attached.

[Legitimate Site Unblocked]akiprotocol.io

**Domain: https://akiprotocol.io

**Details: The site is loyal to its users and we didn't find any malicious activity so far. Let metamask wallet access able to this site.

Adding more info about Aki Network / Aki Protocol.

Aki introduces two layers to organize the web3 world’s information and make it universally accessible and useful.

An open infrastructural multi-chain knowledge base that provides oracle services and rewards data layer contributors - Aki Protocol
A consumer-facing application suite built on top of Aki Protocol with a specific focus on influencer-centered graphs - Aki Network
Whitepaper: https://aki-network.gitbook.io/aki-general-whitepaper/
Twitter: https://twitter.com/aki_protocol
Email: [email protected]

Feel free to DM/email and book a call with us if you have more questions

[Legitimate Site Blocked] Exodus.icu - a Revolt Chat clone

Hello!

I believe exodus.icu was automatically flagged due to its resemblance of exodus.com, or possible past use in phishing activities. I just recently registered the domain 2 days ago and plan to run my own personal instance of the Revolt Chat app. It's currently up and live now, and a few friends alerted me that MetaMask or Phantom are flagging it.

If I could request the flag be removed, that would be great. I also utilize a few subdomains such as https://app.exodus.icu/ https://autumn.exodus.icu/ https://docs.exodus.icu/ https://support.exodus.icu/ https://endpoint.exodus.icu/ and have plans to use a few others in the future.

nft-blocklist.yaml coverage

Hi, thanks for this resource!

For the nft-blocklist, is the coverage ETH only? or are these contracts also malicious in other networks (e.g. MATIC)?

I'm working on an API which tracks malicious domains from a variety of sources, alongside malicious NFT contracts for ETH & MATIC (and AVAX, FTM & BSC in future) at https://github.com/smk762/no_phish_nfts

Happy to coordinate with sharing data back upstream. Do you have any licence or attribution requirements?

Little example how to use Phantom block list with PHP

Somehow blocklist file is not being parsed with Symfony parser so I needed to make some changes. Purpose of this example is to help someone who is struggling to use it with php.

<?php

namespace App\Utils\Nft;

use Symfony\Component\Yaml\Yaml;

class ScamPrevention
{
    const SCAM_URL_SOURCE = 'https://raw.githubusercontent.com/phantom-labs/blocklist/master/blocklist.yaml';

    private static array $scamWebsites = [];

    public static function isScamNft(array $nftMetadata): bool
    {
        if (empty($nftMetadata['external_url'])) {
            return false;
        }

        $website = $nftMetadata['external_url'];
        $website = preg_replace("(^https?://)", "", $website);
        $website = str_replace('www.', '', $website);

        if (in_array($website, self::fetchListOfScamWebsites())) {
            return true;
        }

        return false;
    }

    public static function fetchListOfScamWebsites(): array
    {
        if (!empty(self::$scamWebsites)) {
            return self::$scamWebsites;
        }

        try {
            $scamWebsitesAsYaml = file_get_contents(self::SCAM_URL_SOURCE);
            $parsedWebsites = Yaml::parse(str_replace(': ', '', $scamWebsitesAsYaml));
            $parsedWebsites = str_replace('- url', '', $parsedWebsites);
            self::$scamWebsites = explode(' ', $parsedWebsites);
        } catch (\Throwable $throwable) {
            self::$scamWebsites = [];
        }

        return self::$scamWebsites;
    }
}

How can you test?

<?php

namespace Tests\Unit;

use App\Utils\Nft\NftException;
use App\Utils\Nft\NftHelper;
use App\Utils\Nft\ScamPrevention;
use Tests\TestCase;

class ScamPreventionTest extends TestCase
{
    public function testFetchListOfScamWebsites(){
        $scamWebsites = ScamPrevention::fetchListOfScamWebsites();
        $this->assertIsArray($scamWebsites);
        $this->assertNotEmpty($scamWebsites);
    }

    public function testIsScamNft(){
        $this->assertTrue(ScamPrevention::isScamNft(['external_url' => 'officialnftgift.com']));
        $this->assertFalse(ScamPrevention::isScamNft(['external_url' => 'movsumov.com']));
    }
}

Legitimate site blocked

Hello,

Please remove fatcatsupgrade.com from your blocklist. This is a legitimate site and we will be launching an art upgrade for the FatCats Collection here.

It is a fresh domain so I can see how it was flagged, but I can assure you it is legitimate.

For some proof of my reputation, you can see some code contributions I've made to metaplex and various other projects in the solana ecosystem here. Let me know if you need me to provide any more proof.

metaplex-foundation/candy-machine-ui#12
metaplex-foundation/sugar#348

Error in Blocklisting (BanterBubbles.com)

https://banterbubbles.com/ Hi there guys, hope you're well, we've just noticed our website being flagged as dangerous with malicious activity present.

I assure you this is not the case. Please visit our site and notice there are absolutely no requirements for any metamask or other wallet addresses. It's not even an available option.

Banter Bubbles is a platform we built for users in the Crypto Banter community to track major price movements in Crypto. We allow users to chat through use of their Twitter account.

Please correct this issue as it is causing major issues for our community.

Correspondence will be much appreciated

Best regards
Josh (Product Manager)

Is it correct that netlify.app is on the list?

Hi everyone

I had the error pop up when trying to open my non-blockchain related app on Netlify. Checking down the list, I notice that netlify.app has been added.

Given Netlify is a popular hosting service for front-end apps of all sorts, is it right that the entire netlify.app domain part is included on the list? Especially in a dev environment, using the Netlify autogenerated URL is standard practice.

Thanks

[Legitimate Site Blocked] discord-accounts.ru

Our site discord-accounts.ru poses no danger. We have been working since 2020. We sell clean new automatically registered Discord messenger accounts. According to search engines "google" and "yandex" we have leading positions in CIS countries. Please exclude the site from suspicious.
image

Scam site

crystalplay.io

Scam site using a stealer to steal all data from your computer.

Website domain blocked for no apparent reason

Hi there, my domain solswipe.io has been blocked for no apparent reason.
We have issued and submitted countless documents and even implemented 4 milestone escrow to our mint. So there is technically close to no way that we can perform any funny actions as all our funds will be locked and only unlocked if our community releases it. We have also submitted lots of documents and will continue posting up more information when we have it. And also postponed our mint to september specifically for the intention of providing more supporting documents to ME or community before our mint.

Therefore,
I would like to appeal that the domain gets unblocked thank you.

nft-blocklist.yaml?

Hi,

I can't see any documentation on this, is this working - if so, how does it work?

We are dealing with quite a few scam NFT's with the Tomorrowland project.

Thanks.

Just some general questions

Hey, great work here.

Just reviewing the blocklist, have a few questions

  1. I see a few user report issues for additions, where do the domains added come from?
  2. When adding the domain to the list, how are the domains assessed to be "bad domains"?
  3. Are domains pruned when they expire?
  4. What is the license?
  5. Is there ABP formatted list of eth-blocklist.yaml & blocklist.yaml ? (for those outside of the extension)

Question about a token that is massivly airdropped

Hello @Harii94,

Since a while, there is a "FLIP.GG" Token that is airdropped to many NFT Collection hosted on MagicEden.
Token Id: https://solscan.io/token/VVWAy5U2KFd1p8AdchjUxqaJbZPBeP5vUQRZtAy8hyc

There is 145,756 holders, and it keep have many more as they do airdropping of it regularly. This token promote a flipping website, but there is no way to find if this real of not. We've many report from people annoyed by this airdrop.

What would you suggest to do? Create a PR to add the token only in the blocklist?

Unblock 1inch.dev

Hi 1inch.dev was bought 2 weeks ago by 1inch. Could you please unblock this site?

[Legitimate Site Unblocked] ydeda.pro

Domain: ydeda.pro

Details: This domain belongs to us, we are engaged in SEO services. The domain is more than 7 years old. We are not a member of any phishing sites. We do not do anything crypto related on this domain.

P.S. Our domain consists only of whitelists. Before Metamask we are also now clean

malicious error

Hi, I'm running a dApp and trying to make user to stake their NFT into our vault and earning some rewards, but somehow some users report that an error/warning message shows when they're trying to sign the transaction.

Message like this:
"Phantom believes this transaction is malicious and unsafe to sign ........."

What's the possible reason to make some user's to get a warning like this ?

thanks!

[Legitimate Site Blocked] cryptio.co

Cryptio is an Enterprise-grade accounting, audit and tax software for digital assets. It is not a dangerous website. Please remove cryptio.co from this blocklist as soon as possible.

New scam site

https://apocalypse.pw/

Fake website of a real project. After clicking on the button and entering the password, it throws a stealer virus to download, which drain all funds from wallets.

New scam

meta-worldp2e.com

Another scam site!!

New Scam WebSites

apocalypse.city
celadongame.com
moonwallet.io

apocalypse and celadon already blocked, it’s new domains. MoonWallet - scam wallet, stealer.

all have link on stealer on website.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.