The crypto industry is fighting back against phishing scammers with a new collaborative defense system. On October 21, 2025, the Security Alliance (SEAL) announced the launch of a global real-time phishing defense network in partnership with MetaMask, Phantom, WalletConnect, and Backpack — a move that comes after phishing attacks drained more than $400 million from crypto users in the first half of 2025 alone.
TL;DR
- SEAL partnered with MetaMask, Phantom, WalletConnect, and Backpack to launch a real-time phishing defense network
- Crypto phishing scams stole over $400 million in H1 2025, according to CertiK
- The system uses “Verifiable Phishing Reports” that allow anyone to submit cryptographically verified phishing alerts
- Reports are shared instantly across all participating wallets without requiring central approval
- Drainer groups like Inferno, Angel, Ace, and Riddance are the primary targets of the initiative
How the Defense Network Works
The backbone of the new system is SEAL’s Verifiable Phishing Reports technology. Unlike traditional blocklists that rely on centralized teams to review and flag malicious websites, this new approach allows anyone — from security researchers to everyday users — to submit phishing reports that are automatically verified and distributed across all participating wallets in real time.
The process works through cryptographic attestations. When a user encounters a suspected phishing site, they can submit a report based on the exact content they were served, along with proof that the content was not forged. The system then processes these reports automatically, circumventing the advanced cloaking techniques that modern drainer groups use to evade detection.
“Anyone with a valid report is able to trigger a phishing warning across network participants in real time and without any special permissions,” SEAL stated in its announcement. The alliance describes the concept as building a “decentralized immune system for crypto security.”
The Cat-and-Mouse Game With Drainers
Phishing operators, commonly known as “drainers,” have evolved significantly over the past two years. According to SEAL, these groups now rotate landing pages rapidly when blocklists update, migrate their infrastructure to offshore bulletproof hosting providers, and deploy sophisticated cloaking tools to hide from automated scanners.
“Drainers are a constant cat and mouse game,” said Ohm Shah, a security researcher at MetaMask. He explained that working with SEAL helps wallet teams apply research faster, “effectively throwing a wrench at the drainer’s infra.”
The defense network specifically targets prominent drainer-as-a-service operations including Inferno Drainer, Angel Drainer, Ace Drainer, and Riddance Drainer — groups that have collectively been responsible for hundreds of millions in stolen crypto assets.
Industry Leaders Rally Behind the Initiative
All four participating wallet providers emphasized that collaboration is essential in the fight against phishing. Derek Rein, CTO of WalletConnect, noted that “security best practices must remain at the forefront of wallet development” and that SEAL’s verifiable approach expands protections significantly.
Armani Ferrante, CEO of Backpack, said the partnership is part of their “ongoing mission to make digital asset ownership more secure.” Kim Persson, Senior Engineer at Phantom, added that the collaboration “will strengthen our domain security and better protect our users.”
The partnership builds on existing efforts like the eth-phishing-detect repository and the SEAL Phishing Bot on Telegram, but represents a significant leap in scale and automation. Where previous approaches required manual review by security teams — a process that was time-consuming and prone to error — the new system creates an end-to-end automated pipeline.
SEAL’s Broader Campaign Against Drainers
The phishing defense network is part of a larger campaign by SEAL to combat the drainer ecosystem. In October 2025, the alliance also released the first volume of its “State of Drainers” series, examining prominent groups like Inferno, Rublevka, and Eleven. The report highlights how these operations have adapted by using deceptive scripts, spoofed wallet interactions, and multi-chain targeting across EVM, Solana, Tron, and TON networks.
SEAL has also published its Verifiable Phishing Reporter as an open-source tool on GitHub, encouraging security researchers and community members to contribute to the defense effort. The organization, which operates as a non-profit, is actively seeking additional wallet providers to join the network.
Why This Matters
Phishing remains the single largest cause of crypto losses in 2025, and the problem is getting worse, not better. Drainer groups operate as sophisticated businesses, offering their tools as a service to less technically skilled criminals. The traditional approach of centralized blocklists has proven inadequate against adversaries who can spin up new phishing pages in minutes and move infrastructure across borders.
The SEAL defense network represents a fundamentally different approach: instead of relying on a single team to catch every scam, it crowdsources threat detection across the entire ecosystem. If a phishing site is reported by one person, every wallet in the network can warn its users within seconds. This is the kind of cooperative security infrastructure that the crypto industry has needed for years.
With Bitcoin trading around $114,472 and Ethereum at $4,158 on October 26, 2025, the stakes have never been higher. A single phishing attack can drain a user’s entire portfolio. Initiatives like this one are essential to making crypto safe enough for mainstream adoption.
Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always verify URLs before connecting your wallet and never share your seed phrase with anyone.
The pace of innovation in crypto continues to surprise me
Inferno Drainer was responsible for like 40% of all phishing losses in 2024 and the defense network only launched in october 2025. the gap between threat and response in crypto is measured in hundreds of millions
seal with metamask and phantom sharing verifiable reports sounds like it could hit those drainer groups hard
real time phishing defense across metamask phantom and backpack should cut those 400M losses fast.
verifiable phishing reports shared across wallets without central approval is the right architecture. one compromised reporting key and the whole system falls apart if centralized
Selma B. agree but the real test is speed. Inferno can deploy a new drainer contract in minutes. if the report propagation takes longer than the drain the network is decorative
This is exactly the kind of development the space needs
The best projects are the ones quietly shipping during bear markets
The gap between crypto and TradFi is narrowing fast
verifiable phishing reports without central approval is the right model. blocklists are too slow for drainer groups that rotate domains daily
aya k the 400m losses in h1 make this real time network a must have now
Aya K. right on verifiable reports without central approval. that model actually works.
phishblocker targeting inferno and ace with instant alerts without central approval is smart
aya k the problem isnt report speed, its enforcement. inferno drainer will just spin up 50 new domains the moment one gets flagged. cat and mouse
50 new domains costs maybe 500 bucks to register. the defense network needs to be faster than the domain rotation or its just a fancier blocklist. cryptographic verification helps but speed is the bottleneck
Vera T. domain registration costs 10 bucks not 500. .xyz and .top TLDs are basically free. defense network speed vs domain rotation is an arms race wallets will lose
400M in H1 alone and WalletConnect just now joining the defense network. should have happened after the $200M drain in 2024 but better late than never i guess
watched inferno drainer hit a friend wallet in real time last month. shared blocklist flagged it 4 hours later. 4 hours is an eternity
Interesting perspective — I hadn’t considered that angle before
$400M in 6 months and the response is a shared blocklist. drainer crews rotate domains in minutes. respect the effort but this is a speed arms race wallets already lost
inferno and angel drainer groups targeted specifically. these crews have been operating for months with zero consequences
$400M in six months and the industry is only now building shared blocklists. should have happened after the first $10M
Verifiable Phishing Reports without central approval is the key part. one bad report and every wallet flags a legit site, so there better be consequences for false positives
Kemal Y. false positive risk is huge. one bad report nukes a legit dApp across every wallet simultaneously. needs a staking or slashing mechanism for reporters
Kavya R. staking/slashing for false reports is the only way this works long term. without skin in the game someone will weaponize it against competitor dApps
Inferno, Angel, Ace, Riddance. four drainer groups causing 400M in damage and they probably operate with like 20 people total. wild efficiency
phish_skeptic_ 20 people causing 400M in damage. that is 20M per person. better ROI than most hedge funds lol