Pith. sign in

REVIEW 3 major objections 5 minor 82 references

Cybersquatting in Web3: The Case of NFT

T0 review · 3 major / 5 minor · reviewed 2026-08-16 · deepseek-v4-flash

Pith's one-line read A measurement of 220K Ethereum NFT collections finds 8,019 that imitate 654 popular projects and pulled $59.26 million from over 670,000 victims.

desk verdict A credible first systematic measurement of NFT name-squatting, but the headline victim and profit numbers are unvalidated upper bounds due to an unmeasured-precision filter. read the letter →

arxiv 2504.13573 v1 pith:RMFRSIBT submitted 2025-04-18 cs.CR

classification cs.CR
keywords cybersquattingNFTscamsEthereumnamesquattingcounterfeitNFTsphishingmeasurementstudy
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper claims that cybersquatting—registering names that imitate a well-known brand in order to deceive buyers—has moved from web domains into NFT collections on Ethereum. Using 220K NFT collections and more than 150M tokens, it identifies 8,019 cybersquatting collections aimed at 654 popular projects, and argues they extracted about $59.26 million from over 670,000 victims through mint fees and creator royalties. If true, this means name-based NFT counterfeiting is not anecdotal but a structured economy with at least seven naming tactics and hundreds of organized scam campaigns. The result matters because NFT marketplaces, investors, and creators all rely on collection names as the main way to find and trust assets.

What carries the argument

The carrying object is a four-stage detection pipeline adapted from domain-squatting practice. Stage I selects the top 996 NFT collections by market cap as targets; Stage II feeds their names into three domain-squatting name generators to synthesize a keyword corpus of identical, combination, and mutation variants; Stage III exact- and partial-matches those keywords against all 220K collection names; Stage IV filters false positives by discarding same-team derivatives and pre-official deployments, then keeps a candidate only if at least four of five signals fire: floor price down more than 90% for 30 days, monthly transfers down more than 90% for two months, no social-media activity after the last on-chain event, a malicious external label, or perceptual-hash image similarity (DHash) below 5. The same pipeline produces the seven-tactic taxonomy and the victim/profit accounting, so the paper's headline numbers all flow through this heuristic gate.

What would settle it

Take a random sample of the 8,019 flagged collections, check whether the official project or the marketplace confirmed them as fraud (through removals, spam flags, or victim reports), and see whether users who paid actually believed they were buying the official item. If a large share of flags are legitimate fan projects or abandoned derivatives, the 670K victim count and the $59.26M figure are overestimates.

Watch

Extended reading notes

Core claim

The paper claims that NFT cybersquatting on Ethereum is widespread and organized. From 220,918 NFT collections and 245M transfer events, it identifies 8,019 cybersquatting collections that target 654 of the 996 most valuable NFT projects; these involve 5.5M+ tokens and 1,679,896 transfer events. It further claims that scammers use seven naming tactics—identical name replication, combination squatting, and six mutation variants (character insertion, character omission, case substitution, misspelling substitution, homoglyph, and homophone)—with combination squatting accounting for 67.22% of cases. On the actor side, the paper reports 6,411 distinct scammer addresses, 794 scam campaigns found by clustering shared external links, creator addresses, and exchange deposit addresses, and 670,817 victim addresses. Finally, it claims that 2,255 of these collections were profitable, generating 21.6K ETH (about $59.26 million) from mint fees and creator earnings.

Load-bearing premise

The whole estimate depends on the assumption that a similarly named collection showing four of five warning signs—price collapse, transfer collapse, social-media silence, a malicious label, or near-identical images—was actually created to deceive people, and the paper never measures how often that label is wrong.

Editorial extensions

If this is right

  • Marketplaces can run the name-variant matching and the five-signal filter at listing time, because the manual review step in the paper is described as fully automatable, making real-time blocking of new squatting collections feasible.
  • Name-similarity detectors that rely only on string edit distance (Levenshtein distance) will keep missing most NFT squatting: the paper finds that such a method catches only 424 of 7,316 non-identical cases, so detection needs explicit mutation and combination patterns.
  • Enforcement directed at the few biggest collections would have outsized effect: 10% of profitable cybersquatting collections capture 84.64% of total profit, and 20% of mint-fee-earning collections capture over 90% of mint revenue.
  • Because 81.53% of flagged collections stay active for one day or less, any practical defense has to act within hours of deployment, not after weeks of review.
  • The 794 identified scam campaigns mean takedowns should target groups of collections linked by shared creator addresses, external websites, or exchange deposit addresses, rather than individual contracts in isolation.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Beyond the paper, the same name-generation and signal-filter design should transfer to NFT ecosystems on other blockchains and to name-based Web3 identifiers such as decentralized name registries, where the economic incentive to imitate a well-known name is identical.
  • Beyond the paper, the $59.26M total counts only mint fees and creator royalties; wallet-draining phishing launched from the associated websites could add losses that this measurement does not capture.
  • Beyond the paper, the marketplace takedown response noted in the paper (2,572 of 8,019 flagged collections removed by the time of writing) can serve as independent ground truth: a follow-up precision study could check how many flags the platform confirmed, which would test the heuristic gate.
  • Beyond the paper, since 'NFT', 'official', 'by', and 'collection' are the most frequent combination-squatting suffixes, a simple registration-time blocklist of brand name plus these tokens would plausibly stop most new squats before they mint, a mitigation the paper does not explicitly propose.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The paper presents a measurement study of cybersquatting NFT collections on Ethereum. The authors collect on-chain data for 220,918 NFT contracts and 245M transfer events up to September 2023, build a keyword corpus using domain-squatting tools (URLCrazy, URLInsane, DNSTwist), match those keywords against collection names, and apply a five-heuristic false-positive filter to identify 8,019 cybersquatting collections targeting 654 of 996 popular projects. They characterize seven naming tactics, analyze collection metadata, social media, content theft, and phishing links, cluster creators into 794 possible scam campaigns, and estimate 670,817 victim addresses and $59.26 million in financial exploitation from mint fees and creator earnings. The paper concludes with mitigation proposals and an ethical disclosure that 2,572 of the identified collections were removed by OpenSea after reporting.

Significance. If the headline numbers are validated, this would be the first large-scale, systematic measurement of NFT cybersquatting and a useful reference for marketplace defenses. The paper's strengths are its transparent on-chain data collection from a Geth node, the public data release, the comparison against the prior Levenshtein-distance approach, the identification of several concrete scam-campaign clusters, and the phishing-link analysis with external corroboration from VirusTotal and SlowMist. However, the quantitative claims—8,019 collections, 670K victims, and $59.26 million—all rest on an unvalidated heuristic filter and on an equating of payment with victimization. The paper's contribution is best assessed as a reproducible measurement pipeline and a qualitative taxonomy; the precision of its headline figures is currently not established.

major comments (3)
  1. [§3.3.4 and §7] The Stage IV false-positive filter is the load-bearing component of the headline counts, but its precision is not measured. A collection is counted as cybersquatting when it meets four of five heuristics (price collapse, transfer collapse, social silence, malicious external label, image similarity), which are generic signs of an inactive or failed project and do not by themselves establish deceptive intent. No labeled ground-truth set, inter-annotator agreement, or precision/recall numbers are reported, and Section 7 concedes that false positives cannot be eliminated. Because the 8,019 collections, 670,817 victim addresses, and $59.26 million are all computed from this list, even a modest false-positive rate changes every headline figure. Please provide a validation study—for example, a random sample of flagged and non-flagged candidates reviewed by multiple annotators, and a precision estimate using the 2,572 collections that OpenSea removed after disclosure as a partial ground truth—and report the resulting ranges for all downstream quantities.
  2. [§2 and §6.2] The paper defines victims as 'entities that have direct financial contributions to scammers' and counts every minter and secondary-market buyer as a victim. This equates payment with deception: no evidence is presented that each address was misled, and legitimate purchases of derivative or fan collections (which the Stage IV filter may include) would be counted as losses. Correspondingly, the $59.26 million figure in §6.3 is gross revenue received by the flagged contracts, not demonstrated financial exploitation and not net of any resale proceeds. Please relabel these quantities as 'payer addresses' and 'gross funds received,' and provide a sensitivity analysis that excludes borderline cases (e.g., collections with no malicious label and no phishing link) to show how the victim and profit totals change.
  3. [§3.3.2 and §4.2] The seven-tactic distribution in Table 3 is generated from the same domain-squatting tools (URLCrazy, URLInsane, DNSTwist) used to build the keyword corpus, so the relative frequencies are conditional on the generator's variation space rather than an independent discovery about attacker behavior. For instance, the predominance of combination squatting (67.22%) and the absence of other possible tactics may reflect the fact that these tools do not generate those variations. The Section 7 limitation that 'these names are randomly generated' does not quantify this. Please state this conditioning explicitly when presenting the taxonomy as an answer to RQ1, and ideally report the generator coverage by comparing with a Levenshtein-based or manually curated set of additional squatting variants.
minor comments (5)
  1. [§3.3] The workflow is described as a three-stage method, but the heading in §3.3.4 is labeled 'Stage IV'; please align the numbering.
  2. [Table 3 and §4.1] Table 3's ERC-721 row total is 6,494, while §4.1 states 6,495; the identical-name percentage is reported as 8.76% in Table 3 and 8.77% in the text. These should be reconciled.
  3. [Table 1 and §3.2] Table 1 reports 245,377,798 total transfer events, while §3.2.1 sums to 219,114,287 + 27,548,181 = 246,662,468; similarly, Table 1 reports 98,390,236 market trades while §3.2.2 states 97,902,053. Please reconcile the discrepancies.
  4. [§6.3] The ETH-USD conversion used to obtain $59.26 million from 21.6K ETH is not stated; please report the exchange rate and date, and note that the conversion is time-varying.
  5. [Table 3] The mutation-based squatting subtotal (1,925, or 24.0%) is discussed in the text but not printed in Table 3; adding a subtotal row would help readers verify the arithmetic.

Circularity Check

1 steps flagged · score 4.0 of 10

Tactic taxonomy is generated by the same squatting tools used for candidate discovery; core prevalence and financial figures otherwise rest on on-chain data and are not circular.

  1. renaming known result [§3.3.2 and §4.2 / Table 3]
    "we adopt URLCrazy [34], URLInsane [35], and DNSTwist [36], which are originally designed for domain squatting... we first conduct a thorough review of all mutation strategies utilized by popular tools such as DNSTwist, URLCrazy, and URLInsane... Based on this review, we reclassify or merge the tactics according to their actual effects and how effectively they mimic legitimate NFT collections."

    The keyword corpus that defines what counts as a cybersquatting candidate is produced by the same three tools whose mutation strategies are later 'reviewed' to build the seven-tactic taxonomy. Thus Table 3's distribution (combination 67.22%, omission 13.76%, case substitution 5.69%, etc.) is a histogram over variant classes that were hard-coded into the generators before any data was examined; it cannot independently 'discover' those tactics. The paper even concedes the generator's variation space is incomplete ('we employ domain squatting tools to generate names for NFT squatting... may not encompass all squatting patterns'), so the tactic frequencies are bounded by construction by the generator's output alphabet rather than emerging from an unbiased empirical taxonomy.

full rationale

The headline prevalence and financial claims do not reduce to their inputs: the 8,019 count is an on-chain count of collections whose names matched externally generated squatting keywords and survived the generic filters, and the $59.26M is the sum of mint fees and creator royalties read from transfer events. The Stage IV filter is heuristic and may admit false positives, but that is a precision/correctness risk, not circularity. The one genuinely circular element is RQ1's naming-tactic taxonomy, which is imported from the same URLCrazy/URLInsane/DNSTwist tools used to construct the candidate corpus, and the paper itself flags this recall limitation in §7. The cited prior work [28] shares authors and supplies thresholds, but those thresholds are not the load-bearing derivation of the main result, and there is no uniqueness theorem or fitted-parameter-renamed-as-prediction pattern. Overall, the study is largely self-contained against on-chain data; only the tactic-distribution contribution is partly circular by construction.

Assumptions & free parameters 5 free parameters · 5 assumptions · 0 invented entities

The headline numbers rest on a chain of labeling choices: the target set, the squatting-name generator, the false-positive heuristics, and the victim definition. Each is described, but only some are validated or bounded.

free parameters (5)
  • False-positive filter thresholds = 90% price drop / 30 days; 90% transfer drop / 2 months; 30-day social silence; 4-of-5 vote
    Hand-set in §3.3.4; these thresholds determine which name-matched collections are retained as cybersquatting, so they directly control the 8,019 count.
  • DHash image similarity threshold = Hamming distance < 5
    Chosen as 'conservative' in §5.2.2; changes the image-theft statistics.
  • Deposit clustering parameters = residual < 0.01 ETH; forward within 10,000 blocks
    Hand-picked in §6.1 following Victor et al.; affects the 794 scam-campaign clusters.
  • Target collection set = top 1,000 by OpenSea market cap, deduplicated to 996
    Scope choice in §3.3.1; all prevalence numbers are relative to this Ethereum-only target list.
  • ETH-USD conversion = unstated, implied approximately $2,743/ETH
    The $59.26M figure depends on an unstated exchange rate; the paper does not say whether it is time-varying.
assumptions (5)
  • domain assumption Domain squatting tools (URLCrazy, URLInsane, DNSTwist) generate variants that cover the space of NFT cybersquatting names.
    Invoked in §3.3.2; acknowledged in §7 as possibly incomplete, so the detected set is a lower bound if scammers use other patterns.
  • ad hoc to paper Every address that pays a mint fee or buys from a flagged collection is a victim.
    Definition in §2 and §6.2 equates financial contribution with deception; it is the basis of the 670K figure and is not verified per address.
  • ad hoc to paper The five heuristic indicators distinguish scam collections from legitimate derivatives, parodies, and dead projects.
    False-positive filtering in §3.3.4; precision is asserted, not measured.
  • domain assumption OpenSea top-1,000 market-cap rank identifies the popular projects that scammers target.
    Target list in §3.3.1; scammers could also target mid-cap projects or other chains.
  • domain assumption Royalty percentages in metadata reflect actual creator earnings on secondary sales.
    Creator earnings are computed as royalty% times sale price in §6.3; royalty enforcement varies by marketplace and over time.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Cybersquatting in Web3: The Case of NFT." pith.science (2026). https://pith.science/paper/RMFRSIBT

@misc{pith2026250413573,
  author       = {Pith},
  title        = {Pith review of: Cybersquatting in Web3: The Case of NFT},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/RMFRSIBT}},
  note         = {Machine review of arXiv:2504.13573}
}
abstract

Cybersquatting refers to the practice where attackers register a domain name similar to a legitimate one to confuse users for illegal gains. With the growth of the Non-Fungible Token (NFT) ecosystem, there are indications that cybersquatting tactics have evolved from targeting domain names to NFTs. This paper presents the first in-depth measurement study of NFT cybersquatting. By analyzing over 220K NFT collections with over 150M NFT tokens, we have identified 8,019 cybersquatting NFT collections targeting 654 popular NFT projects. Through systematic analysis, we discover and characterize seven distinct squatting tactics employed by scammers. We further conduct a comprehensive measurement study of these cybersquatting NFT collections, examining their metadata, associated digital asset content, and social media status. Our analysis reveals that these NFT cybersquatting activities have resulted in a significant financial impact, with over 670K victims affected by these scams, leading to a total financial exploitation of $59.26 million. Our findings demonstrate the urgency to identify and prevent NFT squatting abuses.

Figures

Figures reproduced from arXiv: 2504.13573 by the authors.

Figure 1
Figure 1. The lifecycle of NFTs, where solid lines represent function [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. The workflow of identifying cybersquatting NFT collections. [PITH_FULL_IMAGE:figures/full_fig_p005_2.png] view at source ↗
Figure 3
Figure 3. The longitudinal evolution of naming tactics of cybersquatting [PITH_FULL_IMAGE:figures/full_fig_p007_3.png] view at source ↗
Figures from the paper (7 more)
Figure 7
Figure 7. Figure 7: The CDF of cybersquatting NFT collections according to their [PITH_FULL_IMAGE:figures/full_fig_p008_7.png]
Figure 6
Figure 6. Figure 6: The distribution of cybersquatting NFT collections according [PITH_FULL_IMAGE:figures/full_fig_p008_6.png]
Figure 8
Figure 8. Figure 8: The distribution of cybersquatting NFT collections according [PITH_FULL_IMAGE:figures/full_fig_p009_8.png]
Figure 10
Figure 10. Figure 10: The comparison of the number of Twitter followers between [PITH_FULL_IMAGE:figures/full_fig_p010_10.png]
Figure 11
Figure 11. Figure 11: The comparison of the number of tweets between official and [PITH_FULL_IMAGE:figures/full_fig_p010_11.png]
Figure 12
Figure 12. Figure 12: The CDF of cybersquatting NFT collections according to the [PITH_FULL_IMAGE:figures/full_fig_p011_12.png]
Figure 13
Figure 13. Figure 13: The CDF of cybersquatting NFT collections according to the [PITH_FULL_IMAGE:figures/full_fig_p012_13.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

82 extracted references · 76 canonical work pages

  1. [1]

    Wikipedia. non-fungible-token,

    “Wikipedia. non-fungible-token,” 2023. [Online]. Available: https: //en.wikipedia.org/wiki/Non-fungible_token

  2. [2]

    cryptokitties official website,

    “cryptokitties official website,” 2023. [Online]. Available: https: //www.cryptokitties.co/

  3. [3]

    Cryptopunks official website,

    “Cryptopunks official website,” 2023. [Online]. Available: https: //www.larvalabs.com/cryptopunks 14

  4. [4]

    Bored ape yacht club official website,

    “Bored ape yacht club official website,” 2023. [Online]. Available: https://boredapeyachtclub.com/

  5. [5]

    Top nft coins by market cap|coingecko,

    “Top nft coins by market cap|coingecko,” 2023. [Online]. Available: https://www.coingecko.com/en/categories/ non-fungible-tokens-nft

  6. [6]

    Counterfeit money,

    “Counterfeit money,” https://en.wikipedia.org/wiki/Counterfeit_ money, 2024

  7. [7]

    The intersection of crime and non-fungible tokens (nfts),

    “The intersection of crime and non-fungible tokens (nfts),” https://www.conawayandstrickler.com/blog/ the-intersection-of-crime-and-non-fungible-tokens-nfts/, 2023

  8. [8]

    The cybersquatting of nfts: The rise of civil liability,

    M. R. K. G. Cruz, A. Dimitri, and M. A. d. O. A. Camara, “The cybersquatting of nfts: The rise of civil liability,”Boletim do Tempo Presente, vol. 12, no. 01, pp. 23–36, 2023

Show all 82 references
  1. [9]

    Cybersquatting — Wikipedia, the free encyclopedia,

    Wikipedia contributors, “Cybersquatting — Wikipedia, the free encyclopedia,” 2023, [Online; accessed 21-May-2023]. [Online]. Available: https://en.wikipedia.org/w/index.php?title= Cybersquatting&oldid=1155049922

  2. [10]

    Under- standing security issues in the nft ecosystem,

    D. Das, P. Bose, N. Ruaro, C. Kruegel, and G. Vigna, “Under- standing security issues in the nft ecosystem,” in Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, 2022, pp. 667–681

  3. [11]

    Levenshtein distance,

    “Levenshtein distance,” https://en.wikipedia.org/wiki/Levenshtein_ distance, 2024

  4. [12]

    “Azuki,” https://etherscan.io/address/ 0xed5af388653567af2f388e6224dc7c4b3241c544, 2024

  5. [13]

    Azuki nft,

    “Azuki nft,” https://etherscan.io/address/ 0xa7f574df4e752735d7e220d97c5fde9db83a3503, 2024

  6. [14]

    Cryptocars (cars),

    “Cryptocars (cars),” https://etherscan.io/address/ 0x3b3adf632f8c46b824b2499f3f59693516754d49, 2025

  7. [15]

    Cryptodads (dad),

    “Cryptodads (dad),” https://etherscan.io/address/ 0xecdd2f733bd20e56865750ebce33f17da0bee461, 2025

  8. [16]

    Erc-20: Token standard,

    “Erc-20: Token standard,” 2023. [Online]. Available: https: //eips.ethereum.org/EIPS/eip-20

  9. [17]

    Erc-721: Non-fungible token standard,

    “Erc-721: Non-fungible token standard,” 2023. [Online]. Available: https://eips.ethereum.org/EIPS/eip-721

  10. [18]

    Erc-1155: Multi token standard,

    “Erc-1155: Multi token standard,” 2023. [Online]. Available: https://eips.ethereum.org/EIPS/eip-1155

  11. [19]

    Opensea official website,

    “Opensea official website,” https://opensea.io/, 2023

  12. [20]

    Blur: Nft marketplace for pro traders,

    “Blur: Nft marketplace for pro traders,” https://blur.io, 2023

  13. [21]

    Looksrare - nft marketplace,

    “Looksrare - nft marketplace,” https://looksrare.org/, 2023

  14. [22]

    X2y2 marketplace - x2y2.io,

    “X2y2 marketplace - x2y2.io,” https://x2y2.io/, 2023

  15. [23]

    Cryptopunks,

    “Cryptopunks,” https://cryptopunks.app/, 2023

  16. [24]

    Twitter,

    “Twitter,” https://twitter.com//, 2023

  17. [25]

    Discord,

    “Discord,” https://discord.com/, 2024

  18. [26]

    Tweetboost: Influence of social media on nft valuation,

    A. Kapoor, D. Guhathakurta, M. Mathur, R. Yadav, M. Gupta, and P. Kumaraguru, “Tweetboost: Influence of social media on nft valuation,” in Companion Proceedings of the Web Conference 2022, 2022, pp. 621–629

  19. [27]

    Tracking counterfeit cryptocurrency end-to-end,

    B. Gao, H. Wang, P. Xia, S. Wu, Y . Zhou, X. Luo, and G. Tyson, “Tracking counterfeit cryptocurrency end-to-end,” Proceedings of the ACM on Measurement and Analysis of Computing Systems , vol. 4, no. 3, pp. 1–28, 2020

  20. [28]

    Miracle or mirage? a measurement study of nft rug pulls,

    J. Huang, N. He, K. Ma, J. Xiao, and H. Wang, “Miracle or mirage? a measurement study of nft rug pulls,” Proceedings of the ACM on Measurement and Analysis of Computing Systems , vol. 7, no. 3, pp. 1–25, 2023

  21. [29]

    Nft royalties: Unlocking creative earnings,

    “Nft royalties: Unlocking creative earnings,” https://www.kaleido. io/blockchain-blog/nft-royalties, 2024

  22. [30]

    Opensea: Buy crypto collectibles, cryptokitties, decentraland, and more on ethereum,

    “Opensea: Buy crypto collectibles, cryptokitties, decentraland, and more on ethereum,” 2022. [Online]. Available: https://opensea.io/

  23. [31]

    Chainbase api document,

    “Chainbase api document,” 2023. [Online]. Available: https: //docs.chainbase.com/docs

  24. [32]

    [Online]

    “Geth,” 2023. [Online]. Available: https://github.com/ethereum/ go-ethereum

  25. [33]

    Unveiling the paradox of nft prosperity,

    J. Huang, P. Xia, J. Li, K. Ma, G. Tyson, X. Luo, L. Wu, Y . Zhou, W. Cai, and H. Wang, “Unveiling the paradox of nft prosperity,” in Proceedings of the ACM on Web Conference 2024 , 2024, pp. 167–177

  26. [34]

    Urlcrazy,

    “Urlcrazy,” 2023. [Online]. Available: https://github.com/ urbanadventurer/urlcrazy

  27. [35]

    Urlinsane,

    “Urlinsane,” 2023. [Online]. Available: https://github.com/ziazon/ urlinsane

  28. [36]

    Dnstwist,

    “Dnstwist,” 2023. [Online]. Available: https://github.com/elceef/ dnstwist

  29. [37]

    Metaverse hq opensea,

    “Metaverse hq opensea,” 2023. [Online]. Available: https: //opensea.io/collection/metaverse-hq

  30. [38]

    Common english words,

    “Common english words,” 2021. [Online]. Available: https: //github.com/first20hours/google-10000-english

  31. [39]

    A to z: Cryptocurrency glossary & terms - coingecko,

    “A to z: Cryptocurrency glossary & terms - coingecko,” https:// www.coingecko.com/en/glossary, 2025

  32. [40]

    Mobile app squatting,

    Y . Hu, H. Wang, R. He, L. Li, G. Tyson, I. Castro, Y . Guo, L. Wu, and G. Xu, “Mobile app squatting,” in Proceedings of The Web Conference 2020, 2020, pp. 1727–1738

  33. [41]

    The long “taile

    J. Szurdi, B. Kocso, G. Cseh, J. Spring, M. Felegyhazi, and C. Kanich, “The long “taile” of typosquatting domain names,” in 23rd{USENIX} Security Symposium ({USENIX} Security 14), 2014, pp. 191–206

  34. [42]

    mfers collection,

    “mfers collection,” https://opensea.io/collection/mfers, 2024

  35. [43]

    Doodles collection,

    “Doodles collection,” https://opensea.io/collection/doodles-official, 2024

  36. [44]

    A comprehen- sive measurement study of domain-squatting abuse,

    Y . Zeng, T. Zang, Y . Zhang, X. Chen, and Y . Wang, “A comprehen- sive measurement study of domain-squatting abuse,” in ICC 2019- 2019 IEEE International Conference on Communications (ICC) . IEEE, 2019, pp. 1–6

  37. [45]

    “Dhash,” https://github.com/benhoyt/dhash, 2023

  38. [46]

    Leveraging social media sentiments and ethical signals for nft valuation,

    L. Zhang, Y . Quan, J. Cao, K. Z. Zhou, and X. Tong, “Leveraging social media sentiments and ethical signals for nft valuation,” in 2024 IEEE 24th International Conference on Software Quality, Reliability, and Security Companion (QRS-C) . IEEE, 2024, pp. 206–215

  39. [47]

    Understanding nft price moves through social media keywords analysis,

    J. Luo, Y . Jia, and X. Liu, “Understanding nft price moves through social media keywords analysis,” arXiv preprint arXiv:2209.07706, 2022

  40. [48]

    Virustotal official website,

    “Virustotal official website,” 2023. [Online]. Available: https: //www.virustotal.com/

  41. [49]

    Virustotal report for azukix.com,

    “Virustotal report for azukix.com,” https://www.virustotal.com/gui/url/ 4a5a9584a085b8509cb3866a6f0f606fca94105975b250278eae559f71fcab7f, 2024

  42. [50]

    Slowmist official website,

    “Slowmist official website,” 2025. [Online]. Available: https: //www.slowmist.com/

  43. [51]

    Internet archive: Digital library of free & borrowable texts,

    “Internet archive: Digital library of free & borrowable texts,” https: //archive.org/, 2025

  44. [52]

    Who stole my nft? investigating web3 nft phishing scams on ethereum,

    J. Yang, J. Liu, D. Lin, J. Wu, B. Huang, Q. Li, and Z. Zheng, “Who stole my nft? investigating web3 nft phishing scams on ethereum,” IEEE Transactions on Information Forensics and Security , 2024

  45. [53]

    Address clustering heuristics for ethereum,

    F. Victor, “Address clustering heuristics for ethereum,” in Financial Cryptography and Data Security: 24th International Conference, FC 2020, Kota Kinabalu, Malaysia, February 10–14, 2020 Revised Selected Papers 24. Springer, 2020, pp. 617–633

  46. [54]

    Etherscan,

    “Etherscan,” 2022. [Online]. Available: https://etherscan.io/

  47. [55]

    Coincarp ethereum exchange wallets,

    “Coincarp ethereum exchange wallets,” https://www.coincarp.com/ currencies/ethereum/exchange-wallets/, 2024

  48. [56]

    The landscape of domain name typosquatting: Techniques and countermeasures,

    J. Spaulding, S. Upadhyaya, and A. Mohaisen, “The landscape of domain name typosquatting: Techniques and countermeasures,” in 2016 11th International Conference on Availability, Reliability and Security (ARES). IEEE, 2016, pp. 284–289

  49. [57]

    Bitsquatting: Exploiting bit-flips for fun, or profit?

    N. Nikiforakis, S. Van Acker, W. Meert, L. Desmet, F. Piessens, and W. Joosen, “Bitsquatting: Exploiting bit-flips for fun, or profit?” in Proceedings of the 22nd international conference on World Wide Web, 2013, pp. 989–998. 15

  50. [58]

    Soundsquatting: Uncovering the use of homophones in domain squatting,

    N. Nikiforakis, M. Balduzzi, L. Desmet, F. Piessens, and W. Joosen, “Soundsquatting: Uncovering the use of homophones in domain squatting,” in Information Security: 17th International Conference, ISC 2014, Hong Kong, China, October 12-14, 2014. Proceedings 17. Springer, 2014, ...

  51. [59]

    The homograph attack,

    E. Gabrilovich and A. Gontmakher, “The homograph attack,” Com- munications of the ACM , vol. 45, no. 2, p. 128, 2002

  52. [60]

    Cutting through the confusion: A measurement study of homograph attacks

    T. Holgers, D. E. Watson, and S. D. Gribble, “Cutting through the confusion: A measurement study of homograph attacks.” in USENIX Annual Technical Conference, General Track , 2006, pp. 261–266

  53. [61]

    Hiding in plain sight: A longitudinal study of combosquatting abuse,

    P. Kintis, N. Miramirkhani, C. Lever, Y . Chen, R. Romero-Gómez, N. Pitropakis, N. Nikiforakis, and M. Antonakakis, “Hiding in plain sight: A longitudinal study of combosquatting abuse,” in Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security ,...

  54. [62]

    Challenges in decentralized name management: the case of ens,

    P. Xia, H. Wang, Z. Yu, X. Liu, X. Luo, G. Xu, and G. Tyson, “Challenges in decentralized name management: the case of ens,” in Proceedings of the 22nd ACM Internet Measurement Confer- ence, 2022, pp. 65–82

  55. [63]

    The evolution of nonfungible tokens: Complexity and novelty of nft use-cases,

    A. Park, J. Kietzmann, L. Pitt, and A. Dabirian, “The evolution of nonfungible tokens: Complexity and novelty of nft use-cases,” IT Professional, vol. 24, no. 1, pp. 9–14, 2022

  56. [64]

    Non-fungible token (nft): Overview, evaluation, opportunities and challenges,

    Q. Wang, R. Li, Q. Wang, and S. Chen, “Non-fungible token (nft): Overview, evaluation, opportunities and challenges,”arXiv preprint arXiv:2105.07447, 2021

  57. [65]

    The nft hype: what draws attention to non-fungible tokens?

    C. Pinto-Gutiérrez, S. Gaitán, D. Jaramillo, and S. Velasquez, “The nft hype: what draws attention to non-fungible tokens?” Mathematics, vol. 10, no. 3, p. 335, 2022

  58. [66]

    Sok: On the security of non-fungible tokens,

    K. Ma, J. Huang, N. He, Z. Wang, and H. Wang, “Sok: On the security of non-fungible tokens,” arXiv preprint arXiv:2312.08000, 2023

  59. [67]

    De- tecting ponzi schemes on ethereum: Towards healthier blockchain technology,

    W. Chen, Z. Zheng, J. Cui, E. Ngai, P. Zheng, and Y . Zhou, “De- tecting ponzi schemes on ethereum: Towards healthier blockchain technology,” in Proceedings of the 2018 world wide web confer- ence, 2018, pp. 1409–1418

  60. [68]

    Exploiting blockchain data to detect smart ponzi schemes on ethereum,

    W. Chen, Z. Zheng, E. C.-H. Ngai, P. Zheng, and Y . Zhou, “Exploiting blockchain data to detect smart ponzi schemes on ethereum,” IEEE Access, vol. 7, pp. 37 575–37 586, 2019

  61. [69]

    Expose your mask: smart ponzi schemes detection on blockchain,

    S. Fan, S. Fu, H. Xu, and C. Zhu, “Expose your mask: smart ponzi schemes detection on blockchain,” in 2020 International Joint Conference on Neural Networks (IJCNN) . IEEE, 2020, pp. 1–7

  62. [70]

    Mining bytecode features of smart contracts to detect ponzi scheme on blockchain

    X. Shen, S. Jiang, and L. Zhang, “Mining bytecode features of smart contracts to detect ponzi scheme on blockchain.” CMES- Computer Modeling in Engineering & Sciences , vol. 127, no. 3, 2021

  63. [71]

    Cryptocurrency ponzi schemes,

    S. Mukherjee, C. Larkin, and S. Corbet, “Cryptocurrency ponzi schemes,” Understanding cryptocurrency fraud: The challenges and headwinds to regulate digital currencies , vol. 2, p. 111, 2021

  64. [72]

    Data mining for detecting bitcoin ponzi schemes,

    M. Bartoletti, B. Pes, and S. Serusi, “Data mining for detecting bitcoin ponzi schemes,” in 2018 Crypto Valley Conference on Blockchain Technology (CVCBT). IEEE, 2018, pp. 75–84

  65. [73]

    Phishing attacks and preventions in blockchain based projects,

    A. Andryukhin, “Phishing attacks and preventions in blockchain based projects,” in 2019 international conference on engineering technologies and computer science (EnT). IEEE, 2019, pp. 15–19

  66. [74]

    Phishing scam detection on ethereum: Towards financial security for blockchain ecosystem

    W. Chen, X. Guo, Z. Chen, Z. Zheng, and Y . Lu, “Phishing scam detection on ethereum: Towards financial security for blockchain ecosystem.” in IJCAI, vol. 7, 2020, pp. 4456–4462

  67. [75]

    De- tecting phishing scams on ethereum based on transaction records,

    Q. Yuan, B. Huang, J. Zhang, J. Wu, H. Zhang, and X. Zhang, “De- tecting phishing scams on ethereum based on transaction records,” in 2020 IEEE International Symposium on Circuits and Systems (ISCAS). IEEE, 2020, pp. 1–5

  68. [76]

    Blockchain phishing scam detection via multi-channel graph classification,

    D. Zhang, J. Chen, and X. Lu, “Blockchain phishing scam detection via multi-channel graph classification,” in Blockchain and Trust- worthy Systems: Third International Conference, BlockSys 2021, Guangzhou, China, August 5–6, 2021, Revised Selected Papers 3 . Springer, 2021, pp...

  69. [77]

    Who are the phishers? phishing scam detection on ethereum via network embedding,

    J. Wu, Q. Yuan, D. Lin, W. You, W. Chen, C. Chen, and Z. Zheng, “Who are the phishers? phishing scam detection on ethereum via network embedding,” IEEE Transactions on Systems, Man, and Cybernetics: Systems, vol. 52, no. 2, pp. 1156–1166, 2020

  70. [78]

    Crypto-currencies and icos: Are they scams? an empirical study,

    D. Liebau and P. Schueffel, “Crypto-currencies and icos: Are they scams? an empirical study,” An Empirical Study (January 23, 2019), 2019

  71. [79]

    Predicting fraud in initial coin offerings: A mixed methods approach,

    A. Urbaczewski and T. Deng, “Predicting fraud in initial coin offerings: A mixed methods approach,” 2023

  72. [80]

    The dark side of crypto and web3: Crypto-related scams,

    L. W. Cong, K. Grauer, D. Rabetti, and H. Updegrave, “The dark side of crypto and web3: Crypto-related scams,” Available at SSRN 4358572, 2023

  73. [81]

    Characterizing cryptocurrency exchange scams,

    P. Xia, H. Wang, B. Zhang, R. Ji, B. Gao, L. Wu, X. Luo, and G. Xu, “Characterizing cryptocurrency exchange scams,” Comput- ers & Security , vol. 98, p. 101993, 2020

  74. [82]

    Understanding rug pulls: An in-depth behavioral analysis of fraudulent nft creators,

    T. Sharma, R. Agarwal, and S. K. Shukla, “Understanding rug pulls: An in-depth behavioral analysis of fraudulent nft creators,” arXiv preprint arXiv:2304.07598 , 2023. Appendix Data Availability The dataset used in this study has been made publicly available in an anonymized r...

Pith tools

Reviewed August 16, 2026 · model on record in the stance chip above.