Web3 CTI · updated live

Web3 Intel Center

A defender-facing area for latest Web3 threats: wallet drainers, approval phishing, smart contract exploits, malicious token contracts, exchange/bridge compromises, and scam-address intelligence — built from free OSINT first.

exploit incidents
protocols/bridges
crypto indicators

Wallet drainers

Phishing kits, fake airdrops, malicious approvals, seed theft, browser extension theft, and campaign infrastructure.

Approval phishing

Domains, URLs, contract approvals, token permit abuse, and reported scam-address intelligence with provenance.

Smart contract exploits

Bridge, lending, oracle, access-control, flash-loan, and protocol exploit reporting from free OSINT sources.

Scam-address intelligence

Wallets, EVM contracts, transaction hashes, token contracts, ENS names, and Solana/BTC addresses already in the CTI graph.

Web3 threat facets

Pivot the universal feed into defender categories used for Web3 incidents and scam infrastructure.

All Web3 items
confidence
Observed
confidence
Reported/Suspicious
confidence
Corroborated/High confidence
confidence
Confirmed

Latest Web3 threats

View all
No Web3-tagged threats loaded yet. Start by ingesting free OSINT sources, then they will appear here.

Exploit database incidents

View all
No Exploit database incidents loaded yet.

Web3 protocols & bridges

Open products
Protocol/bridge entities appear here after incident materialization.

Crypto indicators

Open indicators
Wallets, contracts, transaction hashes, and ENS names will show here after extraction/backfill.

Threat intelligence surfaces

Web3 abuse records are connected to source-backed threat reports, crypto indicators, affected protocols, bridges, vulnerabilities, and ransomware/actor context where evidence overlaps.