Bitsquatting: domains one bit-flip away
Updated October 3, 2026
A bitsquat differs from your domain by a single flipped bit; no typo is involved, because the error happens inside a device's memory before the DNS query is ever sent. Attackers register these to catch corrupted requests.
- Demonstrated by
- Artem Dinaburg, Black Hat 2011
- Root cause
- DRAM bit errors (heat, radiation, defects)
- Observed traffic
- Real devices resolving mutated names
Every domain is stored as bytes, and every byte lives in hardware that occasionally corrupts it. A single flipped bit in a device’s RAM turns one character into another valid character: r (0x72) into 2 (0x32), so microsoft.com becomes mic2osoft.com. Bitsquatting is the practice of registering the domains those errors produce, so a corrupted query lands on an attacker’s server.
Where the errors come from
DRAM bit flips are a hardware reality, driven by manufacturing defects, heat, cosmic radiation, and age. Artem Dinaburg demonstrated the attack surface at Black Hat USA 2011: he registered bitsquats of frequently resolved domains and logged over seven months of traffic. Real devices arrived: DNS queries and HTTP requests, including Windows update requests, from machines that had silently corrupted the name they meant to ask for.
A follow-up study by Nikiforakis and colleagues at WWW 2013 measured the squatting side of the market. Tracking bitsquat registrations against popular sites over nine months, they found new bitsquatted domains appearing daily, monetized through advertising, affiliate abuse, and malware installation.
Which domains get targeted
The attack rewards query volume, not name recognition. Dinaburg’s original work targeted content-delivery and update infrastructure, domains like fbcdn.net and akamai.com that devices resolve constantly without any human typing. But any brand with frequent resolution is a candidate, and a brand’s own domain carrying login or update traffic is precisely the kind an attacker wants misdirected.
Defense: enumerate the flips
ECC memory prevents the errors on machines that have it, mostly servers, but the client devices doing the resolving rarely do. The defense that remains is the same as for the rest of typosquatting: know the variants before the attacker registers them.
Bit flips are enumerable: for a label of n characters there are at most 6 single-bit flips per character that stay valid, a small fixed set. The lookalike domain generator produces them alongside typos and homoglyphs. notolens’s daily registration matching covers the same set, so a bit-flip registration against your domain surfaces like any other match, ready for the standard registrar abuse report if it starts serving traffic.
Sources
Frequently asked questions
ASCII characters are bytes, and flipping a single bit produces a different valid character. The letter r (0x72) becomes 2 (0x32) when bit 6 flips, so microsoft.com becomes mic2osoft.com. A bitsquatter registers the names a memory error could produce.
Rarely per device, but at internet scale they are constant. Dinaburg's 2011 experiment logged over seven months of real HTTP and DNS traffic to bitsquatted domains, including misdirected Windows update requests, from devices whose memory had corrupted the queried name.
Yes, and this is the one lookalike family where it is practical. A label yields at most six valid one-bit variants per character, a few dozen names for a typical brand, so Dinaburg recommended registering them outright. It covers that exact set only: monitoring still matters for the same flips under other TLDs and for every other lookalike family.
ECC RAM corrects single-bit errors on the machines that have it, which is mainly servers. Most phones, laptops, and consumer devices lack ECC, so the vulnerable population stays enormous and the flips that matter happen on hardware you do not control.
Typosquatting exploits a user's fingers; bitsquatting exploits a machine's memory. The user typed the right address; the device corrupted it. That is why bitsquats target frequently resolved domains (CDN and update endpoints) as much as ones people type.
Related tools and resources
Lookalike Domain Generator
Enumerate every bit-flip and typo variant of your own domain, in your browser.
Typosquatting
The full range of lookalike registration techniques, scale data, and defenses.
How to Report Domain Abuse to a Registrar
Find the sponsoring registrar and submit an actionable abuse report.
Continuous brand monitoring
notolens checks daily registrations across 1,570 TLDs, trademark registers, and app stores. When a lookalike domain, conflicting mark, or copycat app appears, notolens checks it, explains the risk, and hands you the records and possible next steps.