Threat intelligence
IOC feeds, free for everyone.
Indicators from our advisories and incident response — drainer contracts, attacker addresses, phishing domains — published in machine-readable formats so wallets, RPCs, and security tools can block known threats at the edge.
- Indicators
- 41
- Addresses
- 29
- Domains
- 0
- Refresh
- every 5 min
Licence: CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/. Feeds are CORS-enabled and cached for 5 minutes. JSON and blocklists have detached OpenPGP signatures at the same URL + .asc (e.g. /iocs.json.asc), verifiable with our key. Report a false positive to cert@0xcert.com.
Browse
Active indicators
| Indicator | Type | Label | Chain | Advisory | First seen |
|---|---|---|---|---|---|
| 0xed265fc80e4abe42d72d6bfd1623c89dd2d12f544d53d4ca2c9c3d0fefbf2810 | tx | Malicious authorization via Safe execution (GoPlus Security) | Base | 0xCERT-2026-0230 | 2026-10-09 |
| 0xcdfe91301356da873562ef513828a60dba1f569d | address | Exploit contract added to vault borrow allowlist (GoPlus Security) | Base | 0xCERT-2026-0230 | 2026-10-09 |
| 0x0b5126e1bc27c0de77e02e97945760a674edb034 | address | Attacker EOA (GoPlus Security; PeckShield) | Base | 0xCERT-2026-0230 | 2026-10-09 |
| 0x557bfd0e8530fd3e089748ccaabaa7837877f7578b13a377008474f2e367ee8c | tx | Attack transaction, Aave redemption of 1,783.067 wstETH (GoPlus Security) | Base | 0xCERT-2026-0230 | 2026-10-09 |
| 0x0ec75c3be1f55bb08a92421796675e051993cdb6cbc38d5e33cc2b7f6ef2f491 | tx | Attack transaction, first borrow (GoPlus Security) | Base | 0xCERT-2026-0230 | 2026-10-09 |
| 0x5c1febd5047c2a15c37988b6abd5c8b984236dddf6fd24eed96b0f43951ad2c9 | tx | Exploit transaction | Base | 0xCERT-2026-0153 | 2026-10-08 |
| 0x772e73613ffbc845508377fc6ded1137f60ad730aecb2b7c18a2978a84a6ac1 | tx | Price-moving buy in manipulated pool (Phalcon) | Starknet | 0xCERT-2026-0160 | 2026-10-08 |
| 0x741af6efcc55165e89f7ef0b8ebad7e87efeaa8daa3b60dddd62d5dcacae69d | tx | Attacker NSTR/SolvBTC pool creation, one-sided liquidity (Phalcon) | Starknet | 0xCERT-2026-0160 | 2026-10-08 |
| 0xa059aaab82773caf622de9d9a0f2dbf9aa7f3c37 | address | Attacker consolidation address for bridged funds (CertiK) | Ethereum | 0xCERT-2026-0160 | 2026-10-08 |
| 0x06d48ef7ab62c26e3ef1987c322096cd508e9034c82048783a6b438fc1344bc3 | address | Attacker borrow account (CertiK, GoPlus) | Starknet | 0xCERT-2026-0160 | 2026-10-08 |
| 0x6bc9b41bce2b6c08639c16790af064efafa15890c1ebf8cc72df99a577a1cf1 | tx | Manipulated GeckoTerminal oracle price entry (Phalcon) | Starknet | 0xCERT-2026-0160 | 2026-10-08 |
| 0x2460fde607d09f2434d1b4e6d4089c6e1f459f4ce70ba2853d3a37547cdf00e | tx | Borrow at inflated NSTR valuation (Phalcon) | Starknet | 0xCERT-2026-0160 | 2026-10-08 |
| 0x09fd1f5d9f185067a92493e43aa259ea4ab3ad37 | address | BSC theft address (ZachXBT) | BNB Chain | 0xCERT-2026-0151 | 2026-10-08 |
| 0x9bfcca13b4ac907433ac68766e96309ac867f819 | address | Attacker forwarder wallet (Neutron post-mortem) | Ethereum | 0xCERT-2026-0143 | 2026-10-08 |
| secret1mru6cp7ft8cfasaye4g6vum52qygnkq0cgw0az | address | Key used to fund the vote purchase (Neutron post-mortem) | Secret Network | 0xCERT-2026-0143 | 2026-10-08 |
| 0xef6c5a31df984c8569236a0abc1f27580e2a5d54 | address | Attacker collection wallet (Neutron post-mortem) | Ethereum | 0xCERT-2026-0143 | 2026-10-08 |
| neutron1dd25c4sshelrpfs0433apg24c5phrhk8l6n605 | address | Attacker wallet (Neutron post-mortem) | Neutron | 0xCERT-2026-0143 | 2026-10-08 |
| noble1dd25c4sshelrpfs0433apg24c5phrhk8nx0sda | address | Attacker wallet (Neutron post-mortem) | Noble | 0xCERT-2026-0143 | 2026-10-08 |
| cosmos1dd25c4sshelrpfs0433apg24c5phrhk8m96c4n | address | Attacker wallet (Neutron post-mortem) | Cosmos Hub | 0xCERT-2026-0143 | 2026-10-08 |
| osmo1dd25c4sshelrpfs0433apg24c5phrhk8n7fgrp | address | Attacker wallet (Neutron post-mortem) | Osmosis | 0xCERT-2026-0143 | 2026-10-08 |
| axelar1dd25c4sshelrpfs0433apg24c5phrhk8ltvs7j | address | Attacker wallet (Neutron post-mortem) | Axelar | 0xCERT-2026-0143 | 2026-10-08 |
| dydx1dd25c4sshelrpfs0433apg24c5phrhk8ju5u4y | address | Attacker wallet (Neutron post-mortem) | dYdX | 0xCERT-2026-0143 | 2026-10-08 |
| neutron1ekgfga6vv4zdrrjn3dux6f62fuzektfndgaehm | address | Attacker voting wallet (Neutron post-mortem) | Neutron | 0xCERT-2026-0143 | 2026-10-08 |
| noble1ekgfga6vv4zdrrjn3dux6f62fuzektfnp5pn4j | address | Attacker voting wallet (Neutron post-mortem) | Noble | 0xCERT-2026-0143 | 2026-10-08 |
| cosmos1ekgfga6vv4zdrrjn3dux6f62fuzektfnfh5mdu | address | Attacker voting wallet (Neutron post-mortem) | Cosmos Hub | 0xCERT-2026-0143 | 2026-10-08 |
| osmo1erq7tre6nk0jfx203z8ey75g4m7yfrckl3qx87 | address | Attacker key used to sell THORChain refund (Neutron post-mortem) | Osmosis | 0xCERT-2026-0143 | 2026-10-08 |
| cosmos1erq7tre6nk0jfx203z8ey75g4m7yfrckh2nk3v | address | Attacker key used to sell THORChain refund (Neutron post-mortem) | Cosmos Hub | 0xCERT-2026-0143 | 2026-10-08 |
| 0xe149310eb8b1b3d9c471ccd81819d393621fba5c | address | Attacker working wallet (Neutron post-mortem) | Ethereum | 0xCERT-2026-0143 | 2026-10-08 |
| TAvraZZFCZbDSZoyqWWRRsBkFgZqKaCGbK | address | Hacker address (Scam Sniffer) | Tron | 0xCERT-2026-0148 | 2026-10-08 |
| 0xa77e24fe29d16e051e487ef4ea7b056cb05aef76 | address | Hacker address, EVM (Scam Sniffer) | Ethereum | 0xCERT-2026-0148 | 2026-10-08 |
| TBWNguTTgezw9dVorX441C6nDrZpRxYwKD | address | Primary attacker-controlled receiving address (Bitget) | Tron | 0xCERT-2026-0147 | 2026-10-08 |
| t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG | address | Primary attacker-controlled receiving address (Bitget) | Zcash | 0xCERT-2026-0147 | 2026-10-08 |
| rwNhefsz1UQEusxhCvHip3RANinWi4CTck | address | Primary attacker-controlled receiving address (Bitget) | XRP Ledger | 0xCERT-2026-0147 | 2026-10-08 |
| 0x770b10b273fc44fe9197d6bf20f145c2e98463ee | address | Primary attacker-controlled receiving address, EVM (Bitget) | Ethereum | 0xCERT-2026-0147 | 2026-10-08 |
| 0x01eb957e5c7dcddd60f3c875956ccc6fb9bda5fa | address | Attacker EOA (CertiK) | Ethereum | 0xCERT-2026-0154 | 2026-10-08 |
| 0xec997d2ad033277913d6002277353368e8321dcf | address | Attack contract (CertiK) | Ethereum | 0xCERT-2026-0154 | 2026-10-08 |
| 0xb8ecff9c129d8d9331c85558eaeddff29a38c4c16b71a40986acbf8f6febefeb | tx | First Tornado Cash deposit of proceeds (CertiK) | Ethereum | 0xCERT-2026-0154 | 2026-10-08 |
| 0xd4c0b18a058e7f0a12855f30174f4cb1e973c15c886063deab97e1a21f048ac6 | tx | Attacker funding via Tornado Cash withdrawal (CertiK) | Ethereum | 0xCERT-2026-0154 | 2026-10-08 |
| 0x4a587af4213cc345c4c109fbf5fec46f9643183f91a9edf60305380f31ad1167 | tx | Attack contract deployment (CertiK) | Ethereum | 0xCERT-2026-0154 | 2026-10-08 |
| 0xbb6940f7c2a1e68cafbae7bb9b94d09af9af06ec3a114f6996f2cab993f3a88c | tx | Exploit transaction (CertiK) | Ethereum | 0xCERT-2026-0154 | 2026-10-08 |
| 0xf09a13072ed939b79bc25b66aa3a836ea6dcc170 | address | Malicious adapter module used in exploit (CertiK) | Ethereum | 0xCERT-2026-0154 | 2026-10-08 |
Integrate
Two lines to block known threats.
Pull the domain blocklist
curl -s https://www.0xcert.com/iocs/domains.txt | grep -v '^#'
Check an address with jq
curl -s https://www.0xcert.com/iocs.json \ | jq '.indicators[] | select(.value == "0x…")'