Market Cap: $2.1713T 0.84%
Volume(24h): $40.4173B 15.17%
Fear & Greed Index:

35 - Fear

  • Market Cap: $2.1713T 0.84%
  • Volume(24h): $40.4173B 15.17%
  • Fear & Greed Index:
  • Market Cap: $2.1713T 0.84%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top Cryptospedia

Select Language

Select Language

Select Currency

Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos

How to fix "Phishing website warning" in UniSat? (False Positive Fix)

UniSat’s phishing warning flags domains via community reports and heuristics—not real-time analysis—so new or low-traffic dApps may trigger false positives despite being safe.

Apr 01, 2026 at 10:40 pm

Understanding the UniSat Phishing Warning

1. UniSat Wallet displays a phishing website warning when its internal domain reputation system flags a URL as potentially malicious.

2. This mechanism relies on community-submitted reports and automated heuristics rather than real-time behavioral analysis.

3. Legitimate dApp domains—especially newly deployed or low-traffic ones—often trigger false positives due to lack of historical data.

4. The warning does not indicate that the site is compromised, only that it matches patterns associated with known scam domains.

5. Users may encounter this alert when accessing testnet interfaces, custom token explorers, or decentralized exchange frontends hosted on non-mainstream subdomains.

Verifying Domain Authenticity Manually

1. Cross-check the domain’s SSL certificate using browser developer tools to confirm issuance by trusted CAs like Let’s Encrypt or DigiCert.

2. Inspect the site’s source code for hardcoded wallet connection logic pointing exclusively to verified contract addresses on Bitcoin Layer 2 networks.

3. Confirm the presence of a valid uniSat:verified meta tag in the HTML head section, which signals official integration status.

4. Validate the domain’s DNSSEC configuration to ensure no unauthorized delegation or cache poisoning has occurred.

5. Compare the site’s favicon hash against known deployments listed in the UniSat GitHub repository’s verified-dapps.json file.

Submitting a False Positive Report

1. Navigate to the UniSat GitHub Issues page under the “security” label and open a new issue titled “False Positive Report – [Domain Name]”.

2. Include full HTTP headers captured during the warning event, along with curl -I output showing server response codes and security headers.

3. Attach screenshots of the site’s contract interaction logs, showing signed transactions broadcast only to recognized BRC-20 or Ordinals-compatible endpoints.

4. Provide proof of domain ownership via TXT record verification or signed message using the site’s admin wallet address.

5. Reference any prior audit reports from firms like CertiK or OpenZeppelin that cover the frontend’s integrity and backend API endpoints.

Bypassing the Warning Temporarily

1. Click “Advanced” on the warning screen, then select “Proceed to [domain] (unsafe)” after confirming the URL matches expected spelling and TLD.

2. Use UniSat’s built-in dApp browser in incognito mode to avoid cached reputation flags tied to previous browsing sessions.

3. Import the site’s domain into UniSat’s local allowlist via Settings > Security > Custom Allowlist, entering the exact FQDN without protocol prefix.

4. Disable JavaScript temporarily to verify whether the warning persists—some false positives originate from third-party analytics scripts rather than core functionality.

5. Check if the domain resolves to an IP address within known cloud hosting ranges; unexpected VPS allocations often trigger heuristic alerts even for legitimate services.

Frequently Asked Questions

Q: Does clicking “Proceed anyway” expose my private keys?A: No. UniSat never injects signing capabilities into untrusted domains. Wallet interactions remain disabled until explicit user consent is given per transaction.

Q: Can I report multiple domains in one GitHub issue?A: No. Each domain requires individual verification. Submit separate issues with unique evidence packages to maintain audit traceability.

Q: Why does UniSat block subdomains but not the root domain?A: Subdomains are evaluated independently. A clean root domain does not confer trust to dynamically generated subdomains used for phishing campaigns.

Q: Is there a public list of currently flagged domains?A: Yes. The UniSat team maintains a read-only JSON feed at https://unisat.io/api/v1/phishing/domains which updates hourly and includes timestamps and report sources.

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Related knowledge

See all articles

User not found or password invalid

Your input is correct