Skip to content

Bitsquatting: domains one bit-flip away

Updated October 3, 2026

A bitsquat differs from your domain by a single flipped bit; no typo is involved, because the error happens inside a device's memory before the DNS query is ever sent. Attackers register these to catch corrupted requests.

Demonstrated by
Artem Dinaburg, Black Hat 2011
Root cause
DRAM bit errors (heat, radiation, defects)
Observed traffic
Real devices resolving mutated names

Every domain is stored as bytes, and every byte lives in hardware that occasionally corrupts it. A single flipped bit in a device’s RAM turns one character into another valid character: r (0x72) into 2 (0x32), so microsoft.com becomes mic2osoft.com. Bitsquatting is the practice of registering the domains those errors produce, so a corrupted query lands on an attacker’s server.

Where the errors come from

DRAM bit flips are a hardware reality, driven by manufacturing defects, heat, cosmic radiation, and age. Artem Dinaburg demonstrated the attack surface at Black Hat USA 2011: he registered bitsquats of frequently resolved domains and logged over seven months of traffic. Real devices arrived: DNS queries and HTTP requests, including Windows update requests, from machines that had silently corrupted the name they meant to ask for.

A follow-up study by Nikiforakis and colleagues at WWW 2013 measured the squatting side of the market. Tracking bitsquat registrations against popular sites over nine months, they found new bitsquatted domains appearing daily, monetized through advertising, affiliate abuse, and malware installation.

Which domains get targeted

The attack rewards query volume, not name recognition. Dinaburg’s original work targeted content-delivery and update infrastructure, domains like fbcdn.net and akamai.com that devices resolve constantly without any human typing. But any brand with frequent resolution is a candidate, and a brand’s own domain carrying login or update traffic is precisely the kind an attacker wants misdirected.

Defense: enumerate the flips

ECC memory prevents the errors on machines that have it, mostly servers, but the client devices doing the resolving rarely do. The defense that remains is the same as for the rest of typosquatting: know the variants before the attacker registers them.

Bit flips are enumerable: for a label of n characters there are at most 6 single-bit flips per character that stay valid, a small fixed set. The lookalike domain generator produces them alongside typos and homoglyphs. notolens’s daily registration matching covers the same set, so a bit-flip registration against your domain surfaces like any other match, ready for the standard registrar abuse report if it starts serving traffic.

Sources

Frequently asked questions

Related tools and resources

Continuous brand monitoring

notolens checks daily registrations across 1,570 TLDs, trademark registers, and app stores. When a lookalike domain, conflicting mark, or copycat app appears, notolens checks it, explains the risk, and hands you the records and possible next steps.