logo

Zombie linkages are keeping expired domains trusted for years

ID: 3ee3d706-e700-5e87-8b72-e6cad6a73752

STIX ID: report--3ee3d706-e700-5e87-8b72-e6cad6a73752

Feed Name: Help Net Security

Threat Score
60/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Sinisa Markovic

...
...

Researchers analyzed "zombie linkages" across Web PKI, Maven Central, and Ethereum Name Service and found large numbers of lingering trust records that outlive domain ownership. They observed many TLS certificates still served after domains expired or were re-registered (including ~192k tied to expired domains and ~7.3k after re-registration), thousands of Maven namespaces publishing after domain ownership changed (4,842 namespaces tied to expired/transferred domains, with hundreds publishing post-transfer), and ENS on-chain mappings that remained outdated for years (23.8% of sampled on-chain linkages). These persistent records create realistic vectors for impersonation, supply-chain compromise, and misdirected cryptocurrency payments because there is limited automatic revocation or reclamation of the stale bindings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.