Sep 5, 2025

August Updates: Improved Detection and Infrastructure

Detection & Threat Coverage

Google Ads Detection Source

We added a new source for detecting malicious Google Ads, including location and language targeting. This improves coverage for threats tailored to specific geographies.

App Store Scanning & Detection

This month we expanded support for detecting malicious apps on both Apple and Google Play stores in an automated fashion. We now scan app stores daily looking for fake wallet apps and copycat apps.

DexScreener Detection Source

We introduced initial support for detecting copycat tokens via DexScreener search, helping surface early scams in decentralized exchanges.

YouTube Rules Expansion

Improved rule system to auto-approve obvious scams and reduce false positives from legitimate promotions on YouTube. We are now leveraging more metadata from YouTube's API to detect common patterns of behavior used by bots and scammers.

Link Extraction Improvements

Our detection system now extracts links from static and dynamic HTML in a robust way. This improvement will help with threat discovery to make sure that we not only takedown the initial pages that impersonating your brand, but also the malicious links and iframes embedded inside those pages.

Triage System & Organization Configuration

Asset Triage System Rewritten in Rust

We rebuilt our asset triage engine in Rust, resulting in a 100x speed increase for processing incoming threats. This system acts as the first line of defense — processing thousands of URLs, domains, and profiles every few minutes to route them to the right organization. This massive speedup improves our real-time threat triage and ensures faster protection for customers.

Trademark Registration Configuration

Organizations can now upload trademark registration data, helping support providers that require trademark verification during takedown submission.

API Improvements

Asset Parse API

Introduced a new /asset/parse API that exposes our parsing logic to integrators. Use this endpoint to determine what asset type an arbitrary URL has. Read the docs here: https://chainpatrol.com/docs/external-api/asset-parse.

Report Wallet Addresses Across Chains

We now support reporting wallet addresses using the CAIP-2 standard format, allowing for precise attribution across multiple blockchains. This enhancement improves confidence for clients like Coinbase who track malicious contracts and wallets across chains.

Example input:

  • eip155:1:0xabc123... (for Ethereum mainnet)

  • solana:4k3Dyjzvzp8e... (for Solana)

  • etc.


Detection & Threat Coverage

Google Ads Detection Source

We added a new source for detecting malicious Google Ads, including location and language targeting. This improves coverage for threats tailored to specific geographies.

App Store Scanning & Detection

This month we expanded support for detecting malicious apps on both Apple and Google Play stores in an automated fashion. We now scan app stores daily looking for fake wallet apps and copycat apps.

DexScreener Detection Source

We introduced initial support for detecting copycat tokens via DexScreener search, helping surface early scams in decentralized exchanges.

YouTube Rules Expansion

Improved rule system to auto-approve obvious scams and reduce false positives from legitimate promotions on YouTube. We are now leveraging more metadata from YouTube's API to detect common patterns of behavior used by bots and scammers.

Link Extraction Improvements

Our detection system now extracts links from static and dynamic HTML in a robust way. This improvement will help with threat discovery to make sure that we not only takedown the initial pages that impersonating your brand, but also the malicious links and iframes embedded inside those pages.

Triage System & Organization Configuration

Asset Triage System Rewritten in Rust

We rebuilt our asset triage engine in Rust, resulting in a 100x speed increase for processing incoming threats. This system acts as the first line of defense — processing thousands of URLs, domains, and profiles every few minutes to route them to the right organization. This massive speedup improves our real-time threat triage and ensures faster protection for customers.

Trademark Registration Configuration

Organizations can now upload trademark registration data, helping support providers that require trademark verification during takedown submission.

API Improvements

Asset Parse API

Introduced a new /asset/parse API that exposes our parsing logic to integrators. Use this endpoint to determine what asset type an arbitrary URL has. Read the docs here: https://chainpatrol.com/docs/external-api/asset-parse.

Report Wallet Addresses Across Chains

We now support reporting wallet addresses using the CAIP-2 standard format, allowing for precise attribution across multiple blockchains. This enhancement improves confidence for clients like Coinbase who track malicious contracts and wallets across chains.

Example input:

  • eip155:1:0xabc123... (for Ethereum mainnet)

  • solana:4k3Dyjzvzp8e... (for Solana)

  • etc.


Detection & Threat Coverage

Google Ads Detection Source

We added a new source for detecting malicious Google Ads, including location and language targeting. This improves coverage for threats tailored to specific geographies.

App Store Scanning & Detection

This month we expanded support for detecting malicious apps on both Apple and Google Play stores in an automated fashion. We now scan app stores daily looking for fake wallet apps and copycat apps.

DexScreener Detection Source

We introduced initial support for detecting copycat tokens via DexScreener search, helping surface early scams in decentralized exchanges.

YouTube Rules Expansion

Improved rule system to auto-approve obvious scams and reduce false positives from legitimate promotions on YouTube. We are now leveraging more metadata from YouTube's API to detect common patterns of behavior used by bots and scammers.

Link Extraction Improvements

Our detection system now extracts links from static and dynamic HTML in a robust way. This improvement will help with threat discovery to make sure that we not only takedown the initial pages that impersonating your brand, but also the malicious links and iframes embedded inside those pages.

Triage System & Organization Configuration

Asset Triage System Rewritten in Rust

We rebuilt our asset triage engine in Rust, resulting in a 100x speed increase for processing incoming threats. This system acts as the first line of defense — processing thousands of URLs, domains, and profiles every few minutes to route them to the right organization. This massive speedup improves our real-time threat triage and ensures faster protection for customers.

Trademark Registration Configuration

Organizations can now upload trademark registration data, helping support providers that require trademark verification during takedown submission.

API Improvements

Asset Parse API

Introduced a new /asset/parse API that exposes our parsing logic to integrators. Use this endpoint to determine what asset type an arbitrary URL has. Read the docs here: https://chainpatrol.com/docs/external-api/asset-parse.

Report Wallet Addresses Across Chains

We now support reporting wallet addresses using the CAIP-2 standard format, allowing for precise attribution across multiple blockchains. This enhancement improves confidence for clients like Coinbase who track malicious contracts and wallets across chains.

Example input:

  • eip155:1:0xabc123... (for Ethereum mainnet)

  • solana:4k3Dyjzvzp8e... (for Solana)

  • etc.