·
3 min read
Blocking vs takedown: what each one actually stops
Blocking warns people off a scam site in minutes to hours. A takedown removes it at the source in days to weeks. What each stops, and why you need both.

Nikita Varabei
Blocking puts a warning in front of a scam site inside wallets and browsers so people don't use it. A takedown removes the site or account at the source. Blocking is fast and partial. Takedowns are slower and complete. A good response uses both.
Vendors use the two words loosely, and buyers end up comparing numbers that don't measure the same thing. Here's the plain version. For how long each takes by platform, see our takedown timelines.
Side by side
Blocking | Takedown | |
|---|---|---|
What it does | Shows a warning in wallets and browsers before someone uses the site | Removes the site, account or listing at the source |
Who acts | Wallets, browsers and security blocklists | Hosts, registrars and platforms |
Typical speed | Minutes to hours on confirmed sites | Days, sometimes weeks, depending on who has to act |
Coverage | Only people using a protected wallet or browser | Everyone, once it's down |
Works on | Websites and links | Websites, social accounts, bots, apps, ads |
When blocking matters most
In the first hours. A new phishing page does most of its damage early, while it's being pushed hardest. Blocking is the only action that can land inside that window, and it covers every fake account sending people to the same page.
With ChainPatrol, confirmed sites are flagged in 20+ wallets in about 5–10 minutes and in browsers in about 1–3 hours.
When the takedown matters most
For anything that isn't a website. You can't block a fake support account on X or Telegram inside a browser. It has to come down at the platform. Takedowns also matter for sites customers reach through apps or browsers that don't use blocklists.
How to measure each one
Blocking: how many confirmed sites were blocked, and how quickly after confirmation.
Takedowns: how many were filed, how many completed, and which are still live and why.
Honestly, the second list is the one to ask any vendor for, including us. An alert is a to-do. A count of what's actually gone, with the stragglers named, is the result.
Frequently asked questions
Is blocking enough on its own?
No. It protects people inside protected wallets and browsers, but the site and the accounts pointing to it stay live until they're taken down.
Why not just take everything down and skip blocking?
Because takedowns can take days or weeks, and most of the damage happens in the first hours.
Want to see what's blocked and what's still live for your brand? Book a demo or run a free scan.
Nikita Varabei is co-founder and CEO of ChainPatrol. He spends most of his week with fraud and trust and safety teams dealing with impersonation of their brands.
Fakes of your brand already out there?
ChainPatrol finds them, blocks the links in wallets and browsers, and files the takedowns for you.
More from The Impersonation Institute
What a letter of authorization is, and why takedowns wait for it
A letter of authorization lets a vendor file takedowns for you. What goes in one, why platforms ask for it, and how to keep it from slowing you down.

Nikita Varabei
Takedown timelines
Why some phishing takedowns take weeks
Most phishing takedowns finish in days. Slow ones sit with unresponsive hosts and registrars or behind proxies. Why it happens and what to do meanwhile.

Nikita Varabei
Takedown timelines
Registrar vs host vs Cloudflare: who to report a phishing site to, and how fast each acts
Registrars control the domain, hosts the content, and Cloudflare usually neither. Who to report a phishing site to, what each does, and how fast.

ChainPatrol
Takedown timelines



