Skip to content
New breaches tracked daily · via RecentBreachesFor Business
For people who hold on-chain

Your wallet is pseudonymous. Your home address is not.

The blockchain was never the hard part of a wrench attack. Turning a handle into a street address was — and that used to need a person willing to spend an afternoon on you. It no longer does. Start with the free scan: it shows which look-up sites are carrying your details right now, and this page says exactly what we file to get them taken down.

13.1B+ breach records 634 sites · 582 companies we file to Free scan, no card

The off-chain half of the chain got cheap.

Not the clever part — not tracing your transactions.

The boring part afterwards, where a handle becomes a name and a name becomes a street.

That part used to cost somebody an afternoon, and the afternoon was the only thing rationing it.

What already happened

A chatbot read a home address off public property records.

A reporter asked a chatbot for a professor's home address. It said no, then offered a different route and produced the address, what he paid for the house, and his wife's name.

The records were public the whole time.

What changed is how little it now costs to ask.

MIT Technology Review · May 2026
What was measured

About 30 seconds. About 59 cents.

Researchers built a system out of four AI agents, pointed it at ordinary public posts, and measured it.

An AI agent can build a complete profile of one person for about 59 cents.

It takes about thirty seconds.

It works about 120 times faster than a person doing the same research by hand.

arXiv:2505.12402 · ACL 2026 Findings
What the brokers say

The companies selling your address are declaring it themselves.

California now legally requires data brokers to declare whether they sold your data to an AI developer. In the state's 2026 register, 32 of 603 said they did.

California Privacy Protection Agency · 2026 register

One thing we are not going to blur, because a competitor would use it against us and would be right to: that research is a demonstrated capability.

Somebody built it and measured it.

It is not evidence that anyone is running it against you today, and we will not tell you it is.

What it establishes is the price, and the price is the whole point — looking one person up no longer needs a reason.

Every figure, with its source →

The chain, and the one link anybody can actually reach

1Your wallet made a transaction. Public, permanent, and nothing anyone can undo — including us.
2An ENS name, a mint, or a tip address in a bio ties that wallet to a handle. Also permanent.
3You used that handle somewhere else, and that somewhere else had a breach. This is the seam — and it is the one link here you can narrow yourself, for free, today, by not reusing it again.
4The breached record puts a real name next to that email. Nobody can un-leak that. We can show you which breaches it is in.
5The real name is on a look-up listing with a street, a phone number and your relatives’ names. This is the link we file against.
Take step 5 down and the chain stops at a name. That is the entire claim we make — and step 5 is the step that produces an address.

Four things that actually happen, and what removal does to each

Two of these we file against. Two of them we do not fix, and we would rather say so here than have you find out after you have paid.

We file on this

Somebody comes to your door

The bottleneck was never working out that you hold something.

It was getting from a name to an address, and that comes off a look-up listing.

What we do: send authorized-agent removal requests to the companies publishing those listings, and file again when a listing returns.

What we cannot do: property deeds are public records.

If your house is in your own name, that filing is not ours to remove, and no removal service can take it down.

name → look-up listing → street · phone · relatives
Partly ours

Your carrier hands over your number

Someone talks a phone shop into porting your number, then collects the codes.

They need your number and your name — both sold on look-up sites, so removal shrinks the supply.

It does not stop a carrier being talked into it, and no company can promise you that.

Do this whether or not you ever buy anything from us: move your exchange logins off text-message codes to an authenticator app or a hardware key.

It is free, and for this one it does more than we can.

phone + name → carrier → text code → account
We file on this

Your handle becomes your legal name

A handle you used on-chain is a handle you used somewhere else, and one of those places leaked.

The email attaches a real name; the real name attaches an address.

What we do: show you which breaches that identifier appears in, and file against the listings carrying the address half.

What we cannot do: pull the leaked record back.

It is copied and archived, and anyone telling you otherwise is selling you something.

handle → reused email → breach record → name
Not ours

A message written for you specifically

Your balance is on-chain and readable by anyone, so a phishing message can be sized to it. Nothing we take down changes that, and we are not going to imply it does. What removal does change is the personal detail that makes such a message convincing — your street, your employer, your relatives’ names — because that half is bought from the same look-up sites.

on-chain balance → your email → a message written for you
A small steel hardware token lying alone on a dark surface, its keyring loop empty.

Exactly what we file, to whom, and how often

1You sign one authorization. We then act as your authorized agent under California Civil Code §1798.135(c) and the equivalent laws in other states.
2We send removal requests to 582 companies, covering 634 sites. One letter per company — where a company had registered under several names, we write once instead of five times.
3Protection sends up to 100 removal requests a month for you. At least 23 go out in the first 14 days — most of what we can send in that time — or you get your money back.
4The law gives them up to 45 days to act. Most do. Some are slow. A few refuse outright — and we show you which ones, by name, rather than counting them as done.
5Then they rebuild, because rebuilding profiles is the business. California built its own deletion system on the assumption that removal is a standing job, not a one-off: from August 2026 every registered broker must check the state platform at least once every 45 days. So we check again and file again, for as long as you are with us.
That is the whole of it. We control whether the request goes out. We do not control whether a company obeys it, and we are never going to tell you we do.

What we cannot do

Put here, on the page trying to sell you something, because this is the only honest place to put it.

A company willing to tell you what it cannot do is the only kind worth believing about what it can.

We do not read the blockchain.

No wallet analysis, no ENS resolution, no transaction graph.

An earlier version of this page implied otherwise and it was wrong.

The scan runs on an email address, a phone number or a handle, exactly like every other scan we run.

Nobody can un-leak an email address.

If your details were in a breach, they are copied, traded and archived.

No company on earth can pull that back.

We can tell you which breaches you are in and what was in them.

We cannot make them go away, and neither can anyone charging you more than we do.

There are two AI problems. We work on one.

An AI can look up what is published about you — the listings, the records, the sites that sell your address.

Taking those down means there is less to find, and that is our job.

An AI can also guess things you never published, from the way you write.

Nothing we remove touches that, and we are not going to pretend it does.

We guarantee our filing, not their compliance.

We control whether the request leaves the building, and we put a number on that: the 14-day filing guarantee.

We do not control whether a company obeys it.

Our Refund Policy governs, it says the same thing in writing, and it controls over anything on this page.

What you get here that you do not get elsewhere

Not more sites. Not a bigger promise. You can see what is listed before you pay anything, and we tell you where the product stops.

What you need
What you usually get
DoxxScan™
See what is actually listed before paying
Subscribe first, find out after
Free scan — no card, no account
A number attached to the removal work
“Removal from data brokers”, no figure attached
Up to 100 requests a month, to 582 companies
Something owed to you if we do not file
Usually nothing stated
A 14-day filing guarantee, written into the refund policy
Re-filing when a listing comes back
A periodic re-scan, if you ask for one
We file again, for as long as you stay
Wallet or on-chain analysis
Not something removal services do
We do not either — and we say so

Pricing

Start with the free scan.

If you want us to file, Protection is the plan that does it — three identifiers watched.

For most people here that means the email an exchange has, the phone number behind the codes, and one more you choose.

Free scan
FREEno card

See what is published about you before you decide anything.

  • Takes about 15 seconds
  • No account, no card, no wallet connection
  • Shows which sites are carrying your details
  • Shows which breaches that identifier is in
Run my free scan
Pay for the year
$129/yr

The identical product and the identical standing work, billed once a year instead of twelve times — $10.75 a month.

  • Everything in Protection
  • One charge a year, no monthly line on your statement
  • Saves 28% against paying monthly
  • Cancel in two clicks; access runs to the end of the term
Start removals — $129/yr
Already been drained, swatted, or doxxed?
Start with the free scan, right now.
It shows what is already published about you and which sites are holding it. On your own results page you can buy the full report — $9.99 once — for the actual leaked values and a step-by-step fix for each. After an incident the filings are the part that matters, and that is Protection: authorized-agent removal requests across 634 sites run by 582 companies, filed again each time one of them puts you back up. Most come down, some take longer, and a few refuse. On-chain activity keeps making new links to you, so this is a standing job rather than something you finish once.
Run my free scan

Questions we actually get

From holders, builders and operators, mostly right after their first scan.

Do you look at my wallet or my transactions?

No. There is no wallet analysis in this product, no ENS resolution and no transaction graph.

An earlier version of this page implied there was, and that was wrong.

What we scan is an ordinary identifier: an email address, a phone number or a handle.

What we file against is the listings carrying your name and address.

If you want on-chain analytics, buy an on-chain analytics tool; this is not one.

Do I need to connect a wallet or sign anything?

Never. No wallet connection, no message signature, no seed phrase, no hardware prompt.

If a page claiming to be us ever asks for one, it is not us.

The only thing you sign is a written authorization letting us act as your agent with the removal companies, and that is a form, not a transaction.

I use a fresh wallet per protocol. Does that protect me?

It helps on the on-chain side and does nothing on the off-chain side. If any of those wallets touched an ENS name, claimed an airdrop tied to a handle, was funded from an exchange that holds your ID, or got mentioned in a post, the link back is recoverable. Rotating addresses is worth doing and it is not the thing exposing you. The reused handle, the reused email and the phone number are.

Will scanning create a new record anywhere?

No. Nothing is written to any chain, nothing is sent to an exchange, and no identity vendor is contacted about you.

The scan reads breach records and look-up sites.

If you later ask us to file, the removal companies receive your request — which is the point, and which is the only outbound thing that happens.

I am a public builder. My name is already attached. Is it pointless?

The wallet-to-name link is permanent and we cannot retract it.

What we can do is the next link along: the listings that turn that name into a street, a phone number and a list of your relatives.

We cannot hide that you are who you are.

We can make the address materially harder to buy — and for the thing you are actually worried about, the address is the operative fact, not the name.

What is the honest worst case if I buy?

You pay, we file to 582 companies, and a stubborn minority ignore an authorized-agent request.

That happens, and we show you which ones by name instead of quietly counting them as done.

Meanwhile your deed is still a public record, your breached password is still archived, and your on-chain history is still on-chain.

Everything we said we would do, we did — and a determined person with time can still get there.

If that reads like a reason not to buy, it is a fair one, and you are better off knowing now than after the charge.

Can I pay in crypto?

Not today — checkout runs through Stripe.

Crypto payments add a screening layer that takes real integration work, and we would rather ship it properly than half-ship it.

If that is a dealbreaker, email us and we will sort something manually.

Can I cancel?

Yes — from your dashboard, in two clicks, whenever you want.

Cancel mid-cycle and you keep access until the period ends.

Would rather not see a monthly line on your statement at all?

Annual Protection is $129/yr — the same product and the same standing work, billed once a year instead of twelve times.

Refunds are governed by our Refund Policy, which controls over anything said on this page.

Look yourself up before something else does.

About 15 seconds, no card, no account, no wallet connection.

You will see the sites holding your details and the breaches your identifier is in.

Then you can decide whether any of this is worth paying for.

Run my free scan