
Platform Guides7 min read
Antistock, BillGang and SellPass Went Dark: What the DNS Records Show
Antistock, BillGang, SellPass, HoodPay and Forebit all stopped resolving on 3 August 2026, and now advertise FBI seizure nameservers. But the domain registry still delegates every one of them to the operator's own Cloudflare account — which is not what a real court-ordered seizure looks like.
Seven domains went quiet on the same day
On 3 August 2026, the storefronts, dashboards and APIs of Antistock, BillGang and SellPass all stopped answering. So did HoodPay and Forebit. There was no maintenance notice, no migration email and, two days later, still no statement from anyone who ran them.
For sellers this is not an abstraction. Antistock hosted its shops on astck.com; when that domain stopped resolving, every storefront on it went with it. BillGang advertised "roughly 7,500 businesses" and 99.98% uptime on its own marketing pages right up until it went dark.
What makes this case unusual is not the outage. It is what the domains started saying about themselves.
The nameservers say "seized by the FBI"
Every one of the seven domains now advertises the same two nameservers:
$ dig +short NS antistock.io
ns1.fbi.seized.gov.
ns2.fbi.seized.gov.
$ dig +short A antistock.io
(no answer)
fbi.seized.gov is real US government infrastructure. It is the nameserver pair the FBI puts on domains it takes over under a court order, and it has been used in genuine takedowns — the RAMP cybercrime forum in January 2026, among many others. Seeing it on a domain is a strong signal, which is exactly why it is worth checking rather than repeating.
We checked. It does not hold up.
What the registry says, and why that is the part that matters
A domain has two layers of DNS. The registry records which nameservers a domain is delegated to — that is the authoritative fact, held by the registry operator and changed only through the registrar. Inside the zone those nameservers serve, the owner can write whatever records they like, including NS records that name somebody else entirely.
A court-ordered seizure changes the first layer. Anyone with a DNS dashboard login can change the second.
Here is what the registry actually holds for all seven domains, pulled from RDAP on 5 August 2026:
| Domain | Registry delegation | Registry status |
|---|---|---|
| antistock.io | coco + scott .ns.cloudflare.com | clientTransferProhibited |
| astck.com | coco + scott .ns.cloudflare.com | clientTransferProhibited |
| billgang.com | coco + scott .ns.cloudflare.com | clientTransferProhibited |
| billgang.io | coco + scott .ns.cloudflare.com | clientTransferProhibited |
| sellpass.io | coco + scott .ns.cloudflare.com | clientTransferProhibited |
| hoodpay.io | coco + scott .ns.cloudflare.com | clientTransferProhibited |
| forebit.io | coco + scott .ns.cloudflare.com | clientTransferProhibited |
Not one of them is delegated to the FBI. Every one is still delegated to an ordinary Cloudflare nameserver pair — and clientTransferProhibited is a lock the registrant sets on their own domain, not a hold law enforcement obtains.
The control: what a real seizure looks like
Compare that against domains nobody disputes were seized.
nulled.to was taken in Operation Talent in January 2025. Its registry delegation reads:
$ curl -s https://rdap.org/domain/nulled.to | jq -r ".nameservers[].ldhName"
ns1.fbi.seized.gov
ns2.fbi.seized.gov
The delegation itself moved. weleakinfo.com, seized by the DOJ in 2020, additionally carries serverDeleteProhibited, serverTransferProhibited and serverUpdateProhibited — the registry-level holds that stop the former owner touching the domain at all. None of the seven carry any server* hold.
There is also nothing to look at. Real seizures serve a banner: the DOJ and FBI seals, the statute, the case. These seven serve no A record at all, so a browser gets a connection failure. A seizure that publishes nothing is a seizure that has skipped the entire point of publishing a seizure notice.
They were all one account
One more thing falls out of the same records. Cloudflare assigns each account its own nameserver pair, and that pair is effectively an account fingerprint. All seven domains share coco and scott.
SellPass, Antistock, BillGang, HoodPay and Forebit were operated out of a single Cloudflare account. That has been asserted in the community for a while; the registry records are the first place we have seen it confirmed from public data.
The two readings
We will lay out both, because we cannot prove intent from DNS records.
Reading one: this was staged. Someone with access to the DNS account edited the in-zone NS records to name the FBI, deleted the A records, and let the seizure story do the rest. It costs two minutes, it fools a dig NS, and it buys the quiet that a sudden disappearance otherwise does not get. Everything we measured is consistent with this.
Reading two: a real action, incompletely reflected. Law enforcement sometimes works through a hosting provider before the registrar catches up, and a court order can be sealed. If that is what happened, we would expect the registry delegation to move and a banner to appear within days. Neither has, two days in.
The evidence we can verify points at the first. We are not going to state as fact what a court has not.
What we cannot tell you
- Whether anyone stole anything. Reports of platform-held balances vanishing during a "v2 migration", including six-figure claims, are circulating. We cannot audit anyone's wallet and we have not verified a single balance figure.
- Who did this. DNS records show which account holds a domain, not who sat at the keyboard.
- Whether it is coming back. The domains are still registered and still under their owner's delegation. Nothing about the current state is technically permanent.
- Whether a sealed investigation exists. As of 5 August 2026 there is no DOJ press release, no unsealed indictment and no published docket naming any of these platforms.
If you sold on one of these platforms
The dividing line is who was holding the money.
- Funds that settled into your own gateway — your own Stripe, PayPal or crypto wallet — never touched the platform. They are fine. Check those dashboards directly, not through any platform link.
- Platform-held balances and pending payouts were in someone else's custody. Treat them as unrecoverable until proven otherwise, and plan your next month's cash flow on that basis.
- Export nothing through the platform — there is nothing to export from. Rebuild your catalogue from your own records.
- Do not follow "recovery" links. A dead platform with stranded sellers is a phishing magnet. Every "claim your balance" page you are about to be sent is hostile until proven otherwise, and no legitimate recovery process starts in a Telegram DM.
- If real money is gone, file with your local police and — for a US-registered entity — the FBI's IC3 at ic3.gov. Fraud reports are what turn a rumour into a case.
If you bought from a store on one of these platforms
An order that already delivered is done; the key or file you received still works. An order that has not delivered is not going to. If you paid by card or PayPal, open a dispute now rather than waiting — chargeback windows are measured from the transaction date and they do not pause for an outage. If you paid in crypto, there is no recall mechanism.
The shop owner is very likely a victim here too. Most of them found out the same way you did.
What we changed on Shellix
Antistock, BillGang and SellPass are now tier F on our platforms board, marked offline, with their crawlers switched off and their outbound storefront links removed — a link to a dead domain is a link to whoever registers it next.
Nothing has been deleted. Every store, listing and review we already indexed stays exactly where it is and stays searchable, because for a lot of sellers that archive is now the only public record their shop existed. If the platforms come back, re-enabling each one is a single configuration flag.
Check it yourself
None of this requires trusting us. Two commands, thirty seconds:
# What the domain claims about itself
dig +short NS antistock.io
# What the registry actually holds — the part that counts
curl -s https://rdap.identitydigital.services/rdap/domain/antistock.io \
| jq -r ".nameservers[].ldhName, .status[]"
# The control: a seizure nobody disputes
curl -s https://rdap.org/domain/nulled.to | jq -r ".nameservers[].ldhName"
If the second command ever starts returning fbi.seized.gov, the picture has changed and we will update this post.
Method
Every DNS and registry figure in this post was pulled on 5 August 2026 from Google Public DNS (8.8.8.8), the authoritative Cloudflare nameservers for each zone, and RDAP at rdap.identitydigital.services (.io), rdap.verisign.com (.com) and rdap.org (.to). nulled.to and weleakinfo.com are used as positive controls for what a court-ordered seizure looks like in the same records. Wayback Machine captures bound the outage loosely, not precisely: the Internet Archive last captured billgang.com successfully on 1 July 2026 and antistock.io on 10 July 2026, but it crawls these domains only every few weeks. We did not verify any seller balance or loss figure and do not repeat any as fact.
Frequently asked
Was Antistock actually seized by the FBI?
The evidence we can check says no. The domains advertise FBI nameservers inside their own DNS zone, but the registry still delegates every one of them to the operator's own Cloudflare account, none carry a law-enforcement registry hold, and no seizure banner is served. A real seizure — nulled.to, for example — moves the delegation at the registry.
Can anyone put fbi.seized.gov on their own domain?
Yes. NS records inside a zone are written by whoever controls the DNS account, and nothing stops them naming a nameserver they do not control. It changes what a dig NS prints; it does not transfer anything.
Are my funds recoverable?
Money that settled into your own payment gateway was never held by the platform and is unaffected. Platform-held balances and pending payouts were in the operator's custody and should be treated as unrecoverable unless and until something changes.
Are the stores I saved on Shellix gone?
No. We stopped crawling these platforms and removed outbound links to their dead domains, but every store, listing and review already in our index stays and stays searchable.
Were these platforms all run by the same people?
The registry records show SellPass, Antistock, BillGang, HoodPay and Forebit sharing one Cloudflare nameserver pair, which Cloudflare assigns per account. That is consistent with a single operator, and it is public data anyone can re-check.