The URL shortener that makes your links look as suspicious as possible

by dreadswordon 1/15/2026, 3:28 AMwith 148 comments

by postalcoderon 1/15/2026, 5:05 AM

There may actually be some utility here. LLM agents refuse to traverse the links. Tested with gemini-3-pro, gpt-5.2, and opus 4.5.

edit: gpt-oss 20B & 120B both eagerly visit it.

by gnabgibon 1/15/2026, 3:46 AM

Related: A URL shortener not shortening the URL but makes it look very dodgy (434 points, 2023, 100 comments) https://news.ycombinator.com/item?id=34609461

by arjvikon 1/15/2026, 4:47 AM

My favorite link of all time:

https://jpmorgan.c1ic.link/logger_zcGFC2_bank_xss.docm

Definitely not meta

by tcgvon 1/15/2026, 6:12 PM

Hole in one!

I shortened a link and when trying to access it in Chrome I get a red screen with this message:

  Dangerous site
  Attackers on the site you tried visiting might trick you into installing software or revealing things like your passwords, phone, or credit card numbers. Chrome strongly recommends going back to safety.

by latexron 1/15/2026, 12:20 PM

I think it’s perfectly reasonable to make something useless for fun, it’s an interesting idea.

But what I’d like to understand is why there are so many of the same thing. I know I’ve seen this exact idea multiple times on HN. It’s funny the first time, but once it’s done once and the novelty is gone (which is almost immediately), what’s the point of another and another and another?

by bityardon 1/15/2026, 4:39 AM

IIRC, shadyurl was the original version of this. Doesn't seem to be around anymore, though.

by qnleighon 1/15/2026, 8:30 AM

What's up with the creepy ads on this website? It seems like they are actually sketchy ads and not just fake ads for comedic effect. One shows some scammy nonsense about your device being infected and the other links to a real VPN app.

by vhurgon 1/15/2026, 11:16 AM

Please don’t use 3rd party relays for your URLs. It’s bad enough to have your own server, domain, etc. as single points of failure and bottlenecks without adding a 3rd party into the mix, who either themselves or someone that takes over their domain later track users, randomly redirect your users to a malicious site, or just fail.

I know people have fond memories of long ago when they thought surely some big company’s URL shortener would never be taken down and learned from that when it later was.

by caminanteblancoon 1/15/2026, 5:10 AM

I'm not sure what the use case for this is, but I've been using it as a inefficient messaging service with my girlfriend, ie:

https://c1ic.link/campaign_WxjLdF_login_page_2.bat

You seem to be able to encode arbitrary text, so long as it follows [A-Za-z0-9]+\.[A-Za-z0-9]+

by zX41ZdbWon 1/15/2026, 12:58 PM

I would also like to have something like this, but for "vintage" links - something that looks like it was from the late 90s.

I use them in tests, just for fun: https://github.com/ClickHouse/ClickHouse/blob/master/tests/q...

by codemogulon 1/15/2026, 2:57 PM

BRILLIANT! Even Chrome says nope/DANGEROUS to a creepified link to mail.google.com

by jhaldermon 1/15/2026, 6:25 AM

Fantastic! I miss the original ShadyURL.

https://news.ycombinator.com/item?id=31386108

by domoregoodon 1/15/2026, 4:08 AM

For funsies I shortened https://creepylink.com

And got: https://c1ic.link/account_kPvfG7_download_now.bat

by dreadswordon 1/15/2026, 3:28 AM

Saw this on relaunched Digg and figured HN would appreciate it.

by phoe-krkon 1/15/2026, 9:10 AM

I wouldn't call it a shortener, since most of the links it creates are longer than the originals.

What would be a good name here? A URL redirector?

by juliangmpon 1/15/2026, 9:06 AM

This is legit! If you disable your adblock you even get a suspicious ad

by falsedevon 1/15/2026, 4:47 PM

I can't tell if the website works as advertised because I don't want to open the generated links

by dieggsyon 1/15/2026, 6:58 AM

This is fun. Is it not checking for previously submitted URLs though? I can seemingly re-submit the exact same URL and get a new link every time. I would expect this to fill the database unnecessarily but I have no idea how the backend works.

by Avamanderon 1/15/2026, 3:08 PM

It would've been top-notch if it actually sometimes just used Outlook/O365 or similar vendor's "safelinks" redirector that they use.

by bszaon 1/15/2026, 9:53 AM

Yeah but have fun explaining yourself to the police when the author abandons the project and an actual scammer ends up buying up all those domains.

by autoexecon 1/15/2026, 8:51 PM

Every URL shortener is suspicious.

While this seems like it would make it harder for them I wouldn't be surprised if scammers eventually try to abuse this service too and I have no doubt that people would happily click these if they found in them in a phishing email, that said I give the folks behind this a lot of credit for having a way to contact them and report links if that happens.

by zefhouson 1/15/2026, 7:02 PM

My city utility provider used secured-server.biz for billing for a long time. I always thought it was hilarious and very suspicious looking.

by lzapon 1/15/2026, 7:00 AM

I like how old-school HN comment section does not care about creepy links at all. Or link for that matter.

by TomMaszon 1/15/2026, 1:34 PM

This is great. It created a link to my personal site that Firefox blocked me from going to.

by yc784567on 1/15/2026, 7:20 PM

This is cool, since the links are actually short, but for properly suspicious links I prefer phishyurl [1] .

[1] https://news.ycombinator.com/item?id=45295898

edit: fixed typo

by victorevogoron 1/15/2026, 10:39 AM

Just wondering. so you bought c1ic.link and web-safe.link. That's very cool

by rendallon 1/15/2026, 9:14 AM

This is the best article on Wikipedia!

https://c1ic.link/bzSBpN_login_page_2

Edit: Chrome on Android warned me not to visit the site!

by danielpetricaon 1/15/2026, 5:58 PM

As someone who built a standard shortener (coz.jp), this is hilarious. I spent so much time trying to make links look trustworthy; doing the exact opposite is a surprisingly fun concept.

by zakkion 1/15/2026, 7:00 AM

Is this suspicious: https://microsoft.c1ic.link/0B7jqd_invoice.vbs ?

by CupricTeaon 1/15/2026, 3:04 PM

The other day in a Facebook Messenger group chat I tried to link to https://motherfuckingwebsite.com/ as a joke, but Messenger kept blocking it. It's quite overzealous with its blocking.

by fancychancyon 1/15/2026, 4:15 AM

Haha, it's fun. Just thinking, is there some place where creepy links would be better ?

by FuturisticLoveron 1/15/2026, 7:00 AM

I am sharing content using these creepy links to send to office people.

by abhinaion 1/15/2026, 6:58 AM

Please take my upvote. :)

by dizhnon 1/15/2026, 10:56 AM

Firefox is freaking out on some of these. It's hilarious.

by neuroelectronon 1/15/2026, 12:43 PM

/instagram.c1ic.link/mCLIIp_free_vacation_offer.zip

by arthurezendeon 1/16/2026, 12:41 PM

It's so creepy my corporate VPN blocked it

by CGMthrowawayon 1/15/2026, 4:24 AM

Use case? Besides humor and phishing tests

by lzzzamon 1/15/2026, 8:46 AM

I can just say thanks

by virajk_31on 1/15/2026, 12:47 PM

why do creepy links look creepy?...

by thimkerbellon 1/15/2026, 5:47 PM

Add this to "HN for psychopaths" please.

by snehalbaghelon 1/16/2026, 6:35 AM

Imagine someone compromises apps like these and replaces the creepy looking links to actually dangerous links

by lasgaweon 1/16/2026, 6:25 PM

haha I love this

by CrimsonCapeon 1/15/2026, 3:55 AM

It is hilarious and i'm not clicking any link lol.

by fuddleon 1/15/2026, 5:41 AM

lol, I'm not clicking a .vbs link

by manthangupta109on 1/15/2026, 9:25 AM

lol

by pabs3on 1/15/2026, 4:57 AM

Please don't make any more URL shorteners, they are just a bad idea.

https://wiki.archiveteam.org/index.php/URLTeam