Skip to content

[Legitimate Site Blocked] sherwod.xyz - false positive removal request #289076

Description

@sherrhdev

Legitimate domains, IPs, IPFS hashes, or IPNS names

https://sherwod.xyz
https://www.sherwod.xyz

Please explain why this content is legitimate

Hello Security Team,

We request a manual review of the malicious-site classification affecting:

https://sherwod.xyz
https://www.sherwod.xyz

The warning was observed in MetaMask wallet on August 29, 2026. We believe this classification is a false positive.

About the project

SHERBORN is the current phase of the existing SHER NFT ecosystem on Robinhood Chain, chain ID 4663.

The domain sherwod.xyz is the official domain controlled by the project. The current SHERBORN branding and the legacy domain naming are intentional and do not impersonate MetaMask or any third-party platform.

The application allows NFT holders to:

  • connect through RainbowKit and supported wallets;
  • activate selected NFTs by approving and spending the project's $SHER token;
  • receive protocol rewards;
  • claim accumulated $SHER rewards;
  • use the NFT ascension functionality.

Every wallet connection and transaction is initiated explicitly by the user.

Security behavior

The website:

  • never requests seed phrases, private keys, wallet passwords, or recovery information;
  • does not request transactions automatically when the page is opened;
  • does not download executables or browser extensions;
  • does not redirect users to wallet recovery or credential forms;
  • only interacts with the published project contracts;
  • requires explicit wallet confirmation for every on-chain action.

The Claim All action does not send native ETH and does not request a token approval. Activation approval is limited to the $SHER token and the published rewards contract.

We reviewed the production deployment, HTTPS redirects, frontend assets, and wallet interaction flow. We did not find unauthorized redirects, injected scripts, or deceptive wallet behavior.

Official references

Website:
https://www.sherwod.xyz

Official X:
https://x.com/SherwoodsNFT

OpenSea collection:
https://opensea.io/collection/sher-218864784

$SHER on Pons:
https://www.ponsfamily.com/launchpad/0x9962C469C2B9CBaeF14d60BE50e82dF4925fA4aC

Network:
Robinhood Chain, chain ID 4663

NFT contract:
https://robinhoodchain.blockscout.com/address/0x1f605e8c8FD0b85c25190ebaA411F18C373849ed

$SHER token:
https://robinhoodchain.blockscout.com/address/0x9962C469C2B9CBaeF14d60BE50e82dF4925fA4aC

Rewards contract:
https://robinhoodchain.blockscout.com/address/0x605E522CD46260682398ef6830B3BAb5E72f2A6A

Fee router:
https://robinhoodchain.blockscout.com/address/0xF19ea1816d5A8eFcA602abfE4adBB2623D511fE9

Request

Please:

  1. Manually review the domain and its wallet interaction flow.
  2. Identify the detection source or behavior responsible for the warning.
  3. Remove the malicious-site classification or add the domain to the allowlist if the review confirms this is a false positive.

We can provide proof of domain ownership, deployment information, transaction examples, and any additional technical information required.

Thank you.

Is this a duplicate request?

  • I have checked the issues page and confirmed this is not a duplicate request

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs more informationAuthor of PR or issue has been requested for additional information needed for resolution

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions