All questions
Q & A Security · September 3, 2026

What is a punycode phishing attack?

A punycode phishing attack registers an internationalized domain name (IDN) whose Unicode characters render as a Latin-script brand in the address bar, while the actual DNS name is an ASCII-safe xn-- encoding. The MyEtherWallet incident of April 2018 is the canonical case: attackers hijacked BGP routes and served a phishing site whose certificate matched a punycode-encoded lookalike, so the browser padlock stayed green for many victims.

Read the full guide
What Is Typosquatting? (And How Zscaler Found 30,000 Lookalikes)
Typosquatting turns a spelling mistake into an attack surface. Zscaler ThreatLabz recorded 30,000+ lookalike domains targeting the top brands in a single 6-month window — roughly 200 per brand. Homoglyph, TLD-swap, brand-suffix, punycode. Every family explained, with the MyEtherWallet punycode incident as the canonical case.