Editorial mirrorBrand mentions redacted to public IDs. Hover to inspect. Everything else is theatre.How it works
THE ENABLERS REGISTRYRegistrar accountability archive
Archive LiveRead-only public record · No ads · No tracking
ICANN accredited registrar seals stamped NEGLIGENT — enablers accountability poster.
Live feed / archive shell

The feed is live enough for an archive

Fresh cases belong to the upstream operator. This mirror only preserves the stream, strips the self-congratulation, and leaves a clean read-only view behind.

Live intake mirrorRead-only copyWrapped outbound
File /live·Source voice preserved·Brand labels redacted

█ Daily threat activity

Last 30 days, by detection volume.

peak: 01 Jun · 952 detections

Today Daily count
May 07 May 14 May 21 May 28 Jun 05
Daily average 211
Peak (01 Jun) 952
7-day momentum ↑ 101%
Total / 30d 6,711

01 / Featured exposés · this week

Why the registrars bury our reports.

all investigations · /news →
IANA #1479 retaliation hero Retaliation 15 Apr 2026

Investigation · IANA #1479

IANA #1479 killed our Twitter because we told the truth about them.

Two THE ENABLERS REGISTRY X accounts locked under three shifting justifications. Two weeks earlier we documented IANA #1479 sheltering a $20M+ Monero-theft operation now under EU criminal investigation.

9 min · ResearchRead exposé
IANA #3736 bulletproof exposé Registrar 14 Apr 2026

Investigation · IANA #3736 (IANA #4318)

IANA #3736.com: "bulletproof" registrar with €120 in declared revenue.

An ICANN-accredited registrar that calls itself bulletproof in its own DNS TXT record. Estonian shell, €120 revenue, one employee, Belarusian owners — and a week of fresh fake-Elon casino domains.

14 min · ResearchRead exposé
IANA #3765 5000 reports ignored Negligence 11 Apr 2026

Investigation · IANA #3858

IANA #3765: 5,000+ abuse reports, zero takedowns, one excuse.

Top abused registrar in our dataset. 1,865 alive 7+ days after first report, 156 of those re-reported. The "we forwarded your complaint to the registrant" auto-reply is the entire abuse-process.

12 min · ResearchRead exposé
[REDACTED] $20M Monero drainer exposé $20M+ Heist 02 Apr 2026

Investigation · [REDACTED] · Monero drainer

10 years, $20M+ stolen, IANA #1479 never took it down.

Decade-old Monero possibly phishing operation traced from view-key theft to wallet exfiltration. Now under active EU criminal investigation — registrar still hosting derivative domains.

22 min · InvestigationRead exposé
Registrars enabling global scams Pattern 28 Mar 2026

Pattern report · 12 registrars

The registrar abuse response failure — a system, not a glitch.

Cross-registrar pattern of delays, deflection and victim-blaming. Same template responses, same 7-day-plus survival rates, same registrants. "Forwarded to registrant" = the gravestone of every abuse complaint.

18 min · PatternRead pattern

02 / Append log · destroylist

The blacklist scrolls whether you watch or not.

live tail · destroylist/main
updated every <30s · UTC
~/destroylist main $ tail -f list.json UTC 22:50:50 LIVE
$ # Append-only feed. Each row = one new domain entering the blacklist.
$ wc -l list.json
119,230 domains tracked · 0 appended in last 24h
[2026-06-04 00:35:56] + [REDACTED] .info
[2026-06-04 00:33:24] + [REDACTED] .com
[2026-06-04 00:25:50] + [REDACTED] .com
[2026-06-04 00:22:18] + [REDACTED] .com
[2026-06-04 00:17:45] + kreditti.mx .mx
[2026-06-04 00:15:14] + [REDACTED] .com
[2026-06-04 00:12:42] + [REDACTED] .com
[2026-06-03 22:38:19] + [REDACTED] .com
[2026-06-03 22:38:19] + [REDACTED] .com
[2026-06-03 22:38:19] + [REDACTED] .com
[2026-06-03 22:38:19] + [REDACTED]-my.[REDACTED] .com
[2026-06-03 22:38:18] + [REDACTED] .com
[2026-06-03 21:55:54] + [REDACTED] .com
[2026-06-03 21:24:35] + [REDACTED] .com
[2026-06-03 20:44:10] + [REDACTED] .com
[2026-06-03 20:41:38] + [REDACTED] .dev
[2026-06-03 20:34:06] + [REDACTED] .exchange
[2026-06-03 20:34:06] + rewards-jup.pw .pw
[2026-06-03 20:34:05] + [REDACTED] .one
[2026-06-03 20:34:05] + [REDACTED] .com
20 latest entries · 119,230 total domains tail -f list.json

03 / Surface analytics

Where the infrastructure hides — and what it costs you.

7 of 1,189 registrars shown
ranked by abuse volume · last 30 days

Top abused registrars

last 30 days
[REDACTED] 100% of #1 abuser 20,116
[REDACTED] 70.4% of #1 abuser 14,170
[REDACTED] d/b/a IANA #303 26.1% of #1 abuser 5,247
[REDACTED] 20.5% of #1 abuser 4,124
[REDACTED] 20.2% of #1 abuser 4,068
[REDACTED] 19.8% of #1 abuser 3,983
[REDACTED] 17.8% of #1 abuser 3,588

Top abused TLDs · damage dealt

cost burned by scammers
.com $414,900
.dev $134,796
.app $94,665
.xyz $12,404
.io $192,760
.net $45,852
.org $40,788
Total damage / all-time $1,066,441

04 / The dossier · active threats

The dossier — raw, unfiltered, append-only.

20 shown · 119,230 total
newest first · scroll for more
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 04, 2026 00:35
Registrar: [REDACTED]
IP Address: 198.251.84.200
Created: Jun 03, 2026
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 04, 2026 00:33
Registrar: [REDACTED]
IP Address: 198.251.84.200
Created: Jun 04, 2025
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 04, 2026 00:25
Registrar: [REDACTED]
IP Address: 198.251.84.200
Created: Oct 02, 2025
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 04, 2026 00:22
Registrar: [REDACTED]
IP Address: 198.251.84.200
Created: Nov 30, 2024
kreditti.mx Reported
Screenshot of kreditti.mx
[ NO VISUAL DATA ]
SCAM
Detected: Jun 04, 2026 00:17
Registrar: Registrar.eu
IP Address: 198.251.84.200
Created: Apr 05, 2021
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 04, 2026 00:15
IP Address: 198.251.84.200
Created: Apr 25, 2026
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 04, 2026 00:12
IP Address: 198.251.84.200
Created: Jun 02, 2026
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 03, 2026 22:38
Registrar: REGISTRAR_NOT_FOUND
IP Address: 107.189.22.184
Created: N/A
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 03, 2026 22:38
Registrar: REGISTRAR_NOT_FOUND
IP Address: 107.189.22.184
Created: N/A
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 03, 2026 22:38
Registrar: REGISTRAR_NOT_FOUND
IP Address: 107.189.22.184
Created: N/A
Screenshot of [REDACTED]-my.[REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 03, 2026 22:38
Registrar: REGISTRAR_NOT_FOUND
IP Address: 107.189.22.184
Created: N/A
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 03, 2026 22:38
Registrar: [REDACTED]
IP Address: 104.21.24.160
Created: May 31, 2026
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 03, 2026 21:55
Registrar: [REDACTED]
IP Address: 188.114.96.3
Created: May 31, 2026
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 03, 2026 21:24
Registrar: [REDACTED]
IP Address: 172.67.153.87
Created: May 31, 2026
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 03, 2026 20:44
Registrar: [REDACTED]
IP Address: 86.107.77.15
Created: Feb 26, 2026
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 03, 2026 20:41
Registrar: [REDACTED]
IP Address: 172.66.47.172
Created: N/A
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 03, 2026 20:34
Registrar: [REDACTED]
IP Address: 162.241.85.94
Created: May 27, 2026
Screenshot of rewards-jup.pw
[ NO VISUAL DATA ]
SCAM
Detected: Jun 03, 2026 20:34
IP Address: 188.114.96.3
Created: Jun 02, 2026
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 03, 2026 20:34
Registrar: [REDACTED]
IP Address: 27.124.41.45
Created: Jun 03, 2026
[REDACTED] Reported
Screenshot of [REDACTED]
[ NO VISUAL DATA ]
SCAM
Detected: Jun 03, 2026 20:34
Registrar: [REDACTED]
IP Address: 103.227.84.205
Created: Jun 03, 2026

█ Submit a threat

Found one we haven't logged yet?

The bot logs your submission, runs WHOIS + URLScan + screenshot capture, then merges into the public list within minutes. No login. No CAPTCHAs. No filler.

# avg time from submission → public list: ~4 min
# avg time to registrar takedown: ~6 hours
# appeals supported via /appeals — see footer

Archive note

If the page below still says “we” or sounds suspiciously confident, that remains the upstream publisher speaking. TER only preserves the record, strips the house branding, and keeps exits wrapped through the source gate.