# Dragons Eye Lookup > Has a ransomware group claimed this company or domain? Pay-per-lookup against the Dragons Eye ransomware tracker. Every result is an unverified claim from a criminal leak site. Payments: x402 v2, scheme "exact", USDC on Base mainnet (eip155:8453), asset 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, payTo 0x2dAF658B01e257206375798a15832E9f547D65dD. No accounts or API keys. Flow: call the paid URL -> HTTP 402 with a base64 JSON PAYMENT-REQUIRED header -> sign an EIP-3009 USDC authorization for one of `accepts` -> retry with PAYMENT-SIGNATURE -> 200 + PAYMENT-RESPONSE (settlement receipt). Invalid input returns 400 and is never charged; upstream failures return 5xx and are not settled. Client libraries: @x402/fetch (wrapFetchWithPayment), @x402/axios, or any x402 v2 client. ## Paid endpoints - [GET /v1/lookup](https://api.ransomware-tracker.com/v1/lookup) $0.01: Ransomware leak-site claim lookup by company name or domain. Returns ransomware-group claims (group, dates, country, sector, sources) matching the company or domain. Unverified claims from criminal leak sites; commercially reusable sources only. Query: `q`. Example: https://api.ransomware-tracker.com/v1/lookup?q=example.com ## Free endpoints - GET https://api.ransomware-tracker.com/v1/validate?q=: validate/normalize a company name or domain before paying ## Discovery - OpenAPI: https://api.ransomware-tracker.com/openapi.json - x402 manifest: https://api.ransomware-tracker.com/.well-known/x402 - API catalog (RFC 9727): https://api.ransomware-tracker.com/.well-known/api-catalog - Sitemap: https://api.ransomware-tracker.com/sitemap.xml ## Important Every result is labeled "unverified claim from a criminal leak site". Claims are attacker-asserted, not confirmed breaches. Only commercially reusable sources are returned (RansomLook CC BY 4.0; ransomwatch and DragonsEye snapshot, public domain), so found:false is not proof of absence. Do not use results to contact, shame or harm alleged victims.