Is Phantom safe?
Phantom fetches 80+ remotely-controlled feature flags from its own proxy server, allowing behavior changes without an extension update.
On startup, Phantom contacts eppo-proxy.phantom.app/api with a hardcoded API key to retrieve a set of feature flags evaluated per device. These flags gate features including telemetry collection, bug reporting, and trading capabilities. Because flag values are set server-side, Phantom can activate or deactivate functionality for any user at any time without publishing a new extension version.
Who publishes itPhantom - no other listings under this identity, 26 shared hostnames
Phantom - no other listings under this identity, 26 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 26 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Where it sends data
Destinations our analysis observed Phantom contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- eppo-proxy.phantom.app
Phantom sends data to eppo-proxy.phantom.app. No other extension we have analysed sends data here.