After considering what to do, how we can spot honeypot websites, a really difficult task, I believe a community collection of known honeypot websites is a good idea. When many people share knowledge because we might have seen a honeypot website already or know about it, we can share it here, make our knowledge available to protect more community members from getting victim of proven honeypot websites.
General privacy practices, like VPN for example, are also important but here, we will focus to collect proven honeypot websites.
To protect your privacy it's advisable to avoid any proven honeypot website. I've compiled a list of known honeypot websites, what I'm aware of so far, to make aware of it and I’ll expand my list from community feedback.
What's a honeypot website? A honeypot website is a website which is set up and operated to collect certain confidential information on purpose. When people are visiting a honeypot site, various confidential information will be scraped and stored, like your IP address or your entered information but not limited to.
Such data is very valuable for any investigation of crime or business purposes like identifying which wallet belongs to an individual, a company or which interactions an Bitcoin address reveals.
For some cases it might be helpful to catch scammers and hackers but for our privacy, a honeypot website should be avoided.
Examples for honeypot websites can be: - A block explorer website, where IP information is collected from visitors entering Bitcoin address(es), tying IP address and Bitcoin address. Your IP and Bitcoin address(es) will be collected, stored and possibly forwarded, where such data is getting tied and analyzed.
- A Bitcoin mixer, where logs are kept to de-anonymize transactions later again. Once your mix is finished and you are believing your incoming and outgoing transactions are separated, the honeypot operator will still be able to know which coins are yours by connect ingoing and outgoing transaction.
- A software or hardware wallets (closed source), where personal information like IP addresses and Bitcoin address(es) for example are collected, stored and possibly forwarded, where such data is getting tied and analyzed.
In any case, a honeypot software or hardware wallet is always closed source because if it's open source, any experienced coder could find out about it by reviewing code.
Why are honeypot websites dangerous for our privacy? Honeypots are posing a serious danger to our privacy. We might believe it's quite a normal website and our information is treated confidently, while in reality, any of our data will be stored.
In addition to our IP address etc., entered Bitcoin addresses will be scraped, stored and forwarded to any entity. Addresses will get reviewed and address connections will get revealed.
For privacy enhancing services, we might even pay a fee and not only get nothing in return but also have a privacy risk of believing our Bitcoins are mixed but in reality, logs are kept.
In case of a deliberate honeypot website, deem any privacy assurances as disposable.
To avoid getting victim of honeypot websites, we'll create a collection of such websites.
How to contribute to our collection of known honeypot websites? To participate here, you need to give a sufficient proof about any honeypot website. Like an official statement, exposed code or verified insider information.
Any unproven speculations, especially from competing projects are not enough proof to list a website as "proven honeypot website". Such websites might get listed under "contested claims".
Only websites allowed, where visitors are misled and / or are facing an unexpected and deliberate danger of privacy risks compared to competitors.
My collection only covers honeypots related to Bitcoin.
Please note: any website can be a honeypot.