Bitcoin Forum
September 07, 2025, 01:21:32 PM *
News: Latest Bitcoin Core release: 29.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [Warning]: Fake MetaMask  (Read 116 times)
fullfitlarry (OP)
Member
**
Offline Offline

Activity: 78
Merit: 47


View Profile
August 31, 2025, 12:19:46 PM
 #1

What happened: Fake MetaMask

Code:
 https://metamaskio-com-ext.pages.dev/ 

Archived: https://web.archive.org/save/https://metamaskio-com-ext.pages.dev/



https://www.virustotal.com/gui/url/04d2da04c4091964f5fc4645dd11742cb4e9ab9cb5ace562bdcc08630fd80a23

JeromeTash
Legendary
*
Offline Offline

Activity: 2632
Merit: 1360


Heisenberg


View Profile
August 31, 2025, 01:24:07 PM
 #2

Yes, the link is highly suspicious, but I wonder what their endgame is at this point. The actual contents of the page have links to the actual metamask wallet official website so as things stand right now, they can't phish anything.
Maybe the plan is to change the links later once people start trusting the domain?

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET 2.0..██████.IIIIIFASTER & SLEEKER.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
    PLAY NOW    
virasog
Legendary
*
Offline Offline

Activity: 3458
Merit: 1188


Leading Crypto Sports Betting & Casino Platform


View Profile
August 31, 2025, 05:02:59 PM
 #3

Yes, the link is highly suspicious, but I wonder what their endgame is at this point. The actual contents of the page have links to the actual metamask wallet official website so as things stand right now, they can't phish anything.
Maybe the plan is to change the links later once people start trusting the domain?

There must be more planning by the scammers in this case. Since they have the legit Metamask link, this could be to avoid blacklists as the Google Safe browsing will not flag it immediately. Even the antivirus softwares and other security services will inspect it as clean. Also, this can be an attempt to have the domain get indexed by Google and when people search "MetaMask download" or similar terms, their site can show up. However, later they can put the phishing link and launch a broader version of the scam.  Shocked

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
PX-Z
Legendary
*
Offline Offline

Activity: 1932
Merit: 1218


Wallet transaction notifier @txnNotifierBot


View Profile
August 31, 2025, 10:42:51 PM
 #4

Great find! I'm curious where did you found this website? As I see the site uses pages.dev domain which is from cloudlflare itself. Can't they see those devs deploying phishing site on their platform.
And yes, they are using the correct links there, maybe this is just experimental site. Well, anyway, it's still bad practice to download any software from non official websites.

.
 betpanda.io 
 
ANONYMOUS & INSTANT
.......ONLINE CASINO.......
▄███████████████████████▄
█████████████████████████
█████████████████████████
████████▀▀▀▀▀▀███████████
████▀▀▀█░▀▀░░░░░░▄███████
████░▄▄█▄▄▀█▄░░░█▄░▄█████
████▀██▀░▄█▀░░░█▀░░██████
██████░░▄▀░░░░▐░░░▐█▄████
██████▄▄█░▀▀░░░█▄▄▄██████
█████████████████████████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀░░░▀██████████
█████████░░░░░░░█████████
███████░░░░░░░░░███████
████████░░░░░░░░░████████
█████████▄░░░░░▄█████████
███████▀▀▀█▄▄▄█▀▀▀███████
██████░░░░▄░▄░▄░░░░██████
██████░░░░█▀█▀█░░░░██████
██████░░░░░░░░░░░░░██████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀▀▀▀▀▀█████████
███████▀▀░░░░░░░░░███████
██████░░░░░░░░░░░░▀█████
██████░░░░░░░░░░░░░░▀████
██████▄░░░░░░▄▄░░░░░░████
████▀▀▀▀▀░░░█░░█░░░░░████
████░▀░▀░░░░░▀▀░░░░░█████
████░▀░▀▄░░░░░░▄▄▄▄██████
█████░▀░█████████████████
█████████████████████████
▀███████████████████████▀
.
SLOT GAMES
....SPORTS....
LIVE CASINO
▄░░▄█▄░░▄
▀█▀░▄▀▄░▀█▀
▄▄▄▄▄▄▄▄▄▄▄   
█████████████
█░░░░░░░░░░░█
█████████████

▄▀▄██▀▄▄▄▄▄███▄▀▄
▄▀▄█████▄██▄▀▄
▄▀▄▐▐▌▐▐▌▄▀▄
▄▀▄█▀██▀█▄▀▄
▄▀▄█████▀▄████▄▀▄
▀▄▀▄▀█████▀▄▀▄▀
▀▀▀▄█▀█▄▀▄▀▀

Regional Sponsor of the
Argentina National Team
SFR10
Legendary
*
Offline Offline

Activity: 3486
Merit: 3788



View Profile WWW
September 01, 2025, 01:21:19 PM
 #5

At the time of this writing, five other security vendors have flagged it as well [screenshot].

Can't they see those devs deploying phishing site on their platform.
And yes, they are using the correct links there, maybe this is just experimental site.
Without users reporting it to them, it could take some time before they notice such things [unfortunately]. I ran a plagiarism test on its content and it led to another flagged website [more than 50% of its content got matched] with a similar-looking URL [screenshot], so I don't think it's for experimental purposes.


coin-investor
Hero Member
*****
Offline Offline

Activity: 3318
Merit: 620


Leading Crypto Sports Betting & Casino Platform


View Profile
September 01, 2025, 03:53:28 PM
 #6

Great find! I'm curious where did you found this website? As I see the site uses pages.dev domain which is from cloudlflare itself. Can't they see those devs deploying phishing site on their platform.
And yes, they are using the correct links there, maybe this is just experimental site. Well, anyway, it's still bad practice to download any software from non official websites.

It's a Cloudflare Pages, it's a script deployment service by Cloudflare
Their free service plan offers numerous perks, but this is problematic because scammers and hackers can exploit this feature to scam people at no cost.
They should employ parameters to prevent people from abusing their test trial features.



..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
PX-Z
Legendary
*
Offline Offline

Activity: 1932
Merit: 1218


Wallet transaction notifier @txnNotifierBot


View Profile
September 01, 2025, 11:34:29 PM
 #7

It's a Cloudflare Pages, it's a script deployment service by Cloudflare
Their free service plan offers numerous perks, but this is problematic because scammers and hackers can exploit this feature to scam people at no cost.
They should employ parameters to prevent people from abusing their test trial features.
Yes, just like any free script deployment site, all are prone and used to abuse, using different site, tools tend to get victims, etc.
Seriously, it's their responsibility to regularly check those free deployed site at least once a week or so on their platform especially for those sub domain that is similar to existing platforms.

.
 betpanda.io 
 
ANONYMOUS & INSTANT
.......ONLINE CASINO.......
▄███████████████████████▄
█████████████████████████
█████████████████████████
████████▀▀▀▀▀▀███████████
████▀▀▀█░▀▀░░░░░░▄███████
████░▄▄█▄▄▀█▄░░░█▄░▄█████
████▀██▀░▄█▀░░░█▀░░██████
██████░░▄▀░░░░▐░░░▐█▄████
██████▄▄█░▀▀░░░█▄▄▄██████
█████████████████████████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀░░░▀██████████
█████████░░░░░░░█████████
███████░░░░░░░░░███████
████████░░░░░░░░░████████
█████████▄░░░░░▄█████████
███████▀▀▀█▄▄▄█▀▀▀███████
██████░░░░▄░▄░▄░░░░██████
██████░░░░█▀█▀█░░░░██████
██████░░░░░░░░░░░░░██████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀▀▀▀▀▀█████████
███████▀▀░░░░░░░░░███████
██████░░░░░░░░░░░░▀█████
██████░░░░░░░░░░░░░░▀████
██████▄░░░░░░▄▄░░░░░░████
████▀▀▀▀▀░░░█░░█░░░░░████
████░▀░▀░░░░░▀▀░░░░░█████
████░▀░▀▄░░░░░░▄▄▄▄██████
█████░▀░█████████████████
█████████████████████████
▀███████████████████████▀
.
SLOT GAMES
....SPORTS....
LIVE CASINO
▄░░▄█▄░░▄
▀█▀░▄▀▄░▀█▀
▄▄▄▄▄▄▄▄▄▄▄   
█████████████
█░░░░░░░░░░░█
█████████████

▄▀▄██▀▄▄▄▄▄███▄▀▄
▄▀▄█████▄██▄▀▄
▄▀▄▐▐▌▐▐▌▄▀▄
▄▀▄█▀██▀█▄▀▄
▄▀▄█████▀▄████▄▀▄
▀▄▀▄▀█████▀▄▀▄▀
▀▀▀▄█▀█▄▀▄▀▀

Regional Sponsor of the
Argentina National Team
cryptomaniac_xxx
Hero Member
*****
Offline Offline

Activity: 1988
Merit: 645



View Profile
September 03, 2025, 12:01:06 PM
 #8

It's a Cloudflare Pages, it's a script deployment service by Cloudflare
Their free service plan offers numerous perks, but this is problematic because scammers and hackers can exploit this feature to scam people at no cost.
They should employ parameters to prevent people from abusing their test trial features.
Yes, just like any free script deployment site, all are prone and used to abuse, using different site, tools tend to get victims, etc.
Seriously, it's their responsibility to regularly check those free deployed site at least once a week or so on their platform especially for those sub domain that is similar to existing platforms.

True, and now they are also being abused by this criminals. Maybe in the beginning, they didn't thought about it.

But now, it's different, scammers and criminals will take advantage of anything. So the whole ball game have change and hopefully Cloudfare will also adjust and take the responsibility.

Community will have to react as well to report this kind of sites.

Good find by the OP.

 
 RAZED  
| 
 100% 
WELCOME
BONUS
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
| 
 NO 
KYC
| 
  RAZE THE LIMITS    PLAY NOW     
robelneo
Legendary
*
Online Online

Activity: 3724
Merit: 1252


Enjoy 500% bonus + 70 FS


View Profile WWW
September 03, 2025, 10:44:13 PM
 #9

It's a Cloudflare Pages, it's a script deployment service by Cloudflare
Their free service plan offers numerous perks, but this is problematic because scammers and hackers can exploit this feature to scam people at no cost.
They should employ parameters to prevent people from abusing their test trial features.
Yes, just like any free script deployment site, all are prone and used to abuse, using different site, tools tend to get victims, etc.
Seriously, it's their responsibility to regularly check those free deployed site at least once a week or so on their platform especially for those sub domain that is similar to existing platforms.

I'm not familiar with the KYC rules on Cloudflare. Still, if they allow unverified new users to try their free features, then it's likely to be abused. If you undergo verification before using the platform's features, you will be less likely to launch a phishing site because they have your vital information, which authorities could request in the event of an investigation.

They should implement strict verification for new users who want to test those services right away. This is what happened to the Ml domain, which hackers and scammers exploited because it can be used for free without undergoing KYC.


█████████████████████████▄▄▄
████████████████████████▐███▌
█████████████████████████▀▀▀
██▄▄██▄████████████████████████▄███▄
▐██████▐█▌████▌███▌▐███▐███▀▀████▌
▀▀███▌██▌▐████▌▐███
█████▌███▌██████▌
██▐██████████████████▐███▐██████▐███
█████▌████████▐██████████▌███▌██████▌
███▀▀████▀▀████▀▀▀█████▀▀███▀▀█████▀▀


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
|
▄▄█████▄▄
▄████▀█▀████▄
███▀▀▀░▀░▀▀████
██████░░██░░▐████
██████░░░░░░▀████
██████░░███░░████
███▄▄▄░░░▄▄▄███
▀████▄█▄████▀
▀▀█████▀▀



▀▀█████▀▀



▄▄█████▄▄
▄███████████▄
███░░░░░░░░░███
████▀▀▀░░░▀▀▀████
███░▀██▄▄▄██▀░███
█████▄▄░░░▄▄█████
██████░░░██████
▀████▄▄▄████▀
▀▀█████▀▀
▀▀█████████▀▀
▄▄█████▄▄
▄█████▀█████▄
██████▀░▀██████
██████░░░░░██████
█████▄░░░░░▄█████
█████▄▀▄▄▄▀▄█████
█████▄░░░▄█████
▀█████▄█████▀
▀▀█████▀▀



▀▀█████▀▀
 
LICENSED CRYPTO
CASINO & SPORTS
████
██
██
██
██
██
██
██
██
██
██
██
████
█████████████████████████████████████████████████████████
 
PLAY AND WIN
ROLLS᠆ROYCE

█████████████████████████████████████████████████████████
██████████████████████████████████████████
▄▄▄█████████████▌▐░████
▄▄█▄▄▄▄▄▄███████████████▀▀░▌▐█████
▄▄▀▀▀▄░░░░░░▐██▄▄▄▄▄▄▄░░▄▄▄▄████▄▄▀███
▄▀▀▌▄█████████▌██▌█▀▀▀█▀▐▌▐██████████████
▌█▀▌▌▌▌▌▌▌▌▌▌▌▌█▀░▄▄▄▄▄▄▀░▐▀██▀▀█████████
▐▀▀▀▌▌▌▌▌▌▌▌▌▌▌▌█▄▄▄▄▄▄▄░░░███▀█▀▄░▀█░████
▐▀▀▀█▄▄▄▄▄▄▄▄▄▄▄▀▀░░░░░░░░░███▌█▐▀▄▄▀█░███
█▄▄▄▌░░░░░░░░░░▐▄▄▄▄▄▄▄▄▄░░██▄█▀█▀▄▄██████
▐▄▄▄▀███████████▌░▄▄▄▄▄▄█▌░█▄▄█░▐▀▄▄▐█▄▄██
▐▀▀▀█▄▄▄▄▄▄▄▄▄▄▄▀▀▄▀▀▀▀▀▀░░░█▄▀██▀▄▀▐█████
▀█████▀█▀███▀▀▀▀▀▀▀▀▀▀▀▀████░█▌█▌▀▄▀▀▀▀██
██████████████████████████████████████████
..WELCOME BONUS..
500% + 70 FS
 
PX-Z
Legendary
*
Offline Offline

Activity: 1932
Merit: 1218


Wallet transaction notifier @txnNotifierBot


View Profile
September 03, 2025, 11:30:54 PM
 #10

I'm not familiar with the KYC rules on Cloudflare. Still, if they allow unverified new users to try their free features, then it's likely to be abused. If you undergo verification before using the platform's features, you will be less likely to launch a phishing site because they have your vital information, which authorities could request in the event of an investigation.

They should implement strict verification for new users who want to test those services right away. This is what happened to the Ml domain, which hackers and scammers exploited because it can be used for free without undergoing KYC.
I don't think there is a KYC asking different personal info aside from name and email on that free service of cloudlflare. Actually you can even put different name and birthday etc. since there's no ID verification. Also, even it's not That's why its probably exploited.

There are already many reports about the site being exploited, they should do more work to avoid it or lessen those.

https://www.fortra.com/blog/cloudflare-pages-workers-domains-increasingly-abused-for-phishing

.
 betpanda.io 
 
ANONYMOUS & INSTANT
.......ONLINE CASINO.......
▄███████████████████████▄
█████████████████████████
█████████████████████████
████████▀▀▀▀▀▀███████████
████▀▀▀█░▀▀░░░░░░▄███████
████░▄▄█▄▄▀█▄░░░█▄░▄█████
████▀██▀░▄█▀░░░█▀░░██████
██████░░▄▀░░░░▐░░░▐█▄████
██████▄▄█░▀▀░░░█▄▄▄██████
█████████████████████████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀░░░▀██████████
█████████░░░░░░░█████████
███████░░░░░░░░░███████
████████░░░░░░░░░████████
█████████▄░░░░░▄█████████
███████▀▀▀█▄▄▄█▀▀▀███████
██████░░░░▄░▄░▄░░░░██████
██████░░░░█▀█▀█░░░░██████
██████░░░░░░░░░░░░░██████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀▀▀▀▀▀█████████
███████▀▀░░░░░░░░░███████
██████░░░░░░░░░░░░▀█████
██████░░░░░░░░░░░░░░▀████
██████▄░░░░░░▄▄░░░░░░████
████▀▀▀▀▀░░░█░░█░░░░░████
████░▀░▀░░░░░▀▀░░░░░█████
████░▀░▀▄░░░░░░▄▄▄▄██████
█████░▀░█████████████████
█████████████████████████
▀███████████████████████▀
.
SLOT GAMES
....SPORTS....
LIVE CASINO
▄░░▄█▄░░▄
▀█▀░▄▀▄░▀█▀
▄▄▄▄▄▄▄▄▄▄▄   
█████████████
█░░░░░░░░░░░█
█████████████

▄▀▄██▀▄▄▄▄▄███▄▀▄
▄▀▄█████▄██▄▀▄
▄▀▄▐▐▌▐▐▌▄▀▄
▄▀▄█▀██▀█▄▀▄
▄▀▄█████▀▄████▄▀▄
▀▄▀▄▀█████▀▄▀▄▀
▀▀▀▄█▀█▄▀▄▀▀

Regional Sponsor of the
Argentina National Team
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!