Cloudflare's Legit Wallet Looks So Phishy That Even Experts Get Fooled

Security Is Hard, Y'all

Cloudflare's Legit Wallet Looks So Phishy That Even Experts Get Fooled

A security expert nearly fell for a phishing scam—until discovering the suspicious site was actually Cloudflare's new Wallet product. The episode reveals how legitimate services can mimic attack patterns, making it brutally hard for users and reputation services to tell real from fake. The author urges developers to follow best practices and users to stay vigilant.

When legitimate websites sometimes act very very phishy, consider how hard it must be for URL Reputation services like Microsoft SmartScreen and Google SafeBrowsing to block malicious sites without false positives as millions of new sites are added to the web every week.
  1. yellow_lead

    At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no.

    > There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt.

    What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?

  2. ozim

    Web Developers, please follow every best practice, I’m begging you

    Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas.

    No one is asking Web Developers about their opinion man.

    STOP making everything developers fault.

  3. 63stack

    My main takeaway from this is not that "security is hard" but that cloudflare is pretty incompetent.

  4. epochbtc

    Ironically, this might be at least partially because the internal security controls at Cloudflare for using or provisioning new domains/subdomains is so difficult and arduous that the team decided the fastest way to go to market is to get an entirely new domain. Possible bonus that the official bug bounty program won't apply either, since it's on a new domain so any vulnerabilities found won't have to be paid out (as much).

  5. 1970-01-01

    This isn't a secfail. Why is pay.cloudflare.com so hard to establish? Why does marketing always get to overpower engineering? I expect Cloudflare services to avoid some sketchy .pay TLD for exactly the reasons this person went through.

  6. andremendes

    What a ride of a read. I was 100% it was phishing and I got really surprised to find out it wasn't.

  7. Insimwytim

    The Cloudflare folks apparently want security issues reported via HackerOne (which wouldn’t let me log in because the Cloudflare CAPTCHA HackerOne uses seems to be broken…).

    That's just gold

  8. stymaar

    So it's not just FedEx[1] who does that, but also one of the most important tech company…

    [1]: https://www.troyhunt.com/thanks-fedex-this-is-why-we-keep-ge...

More from this day

2026-08-04