Phishing links masquerading as "Cloudflare verification" hit meme-coin listing pages, draining traders' wallets
AI Market Summary
A wave of sophisticated phishing campaigns is exploiting meme coin listing pages by injecting fake "Cloudflare verification" prompts that trigger malware and drain wallets, with reported losses as high as ~$600k. The issue appears linked to aggregation platforms auto-pulling mutable token metadata links (e.g., DexScreener), creating a scalable attack surface during heightened onchain meme trading. Near-term, this raises operational risk and can dampen speculative flows in meme coins.
Impact level
● Medium
Affected assets
DOGE/USDT-3.73%
AI Insight · DOGE/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
BlockBeats, Sept. 16 — As meme-coin markets rally and on-chain trading activity accelerates, phishing attempts have surged alongside the heat. Multiple reports say highly realistic malicious links are now appearing directly on meme-coin listing and "official website" pages, trapping even experienced traders.
Crypto KOLs @insidecalls and @cladzsol said that while scanning meme coins on-chain, they opened a token's homepage and were met with a "Cloudflare verification" prompt. After following the steps to "complete verification," their on-chain funds were stolen. @cladzsol reported losses of about $600,000.
BlockBeats found similar setups across several newly popular meme coins: users are redirected to a page styled as "Cloudflare verification" that is in fact a phishing link. Following the prompts can trigger the download and execution of malicious scripts, ultimately leading to asset losses.
The issue appears widespread, which BlockBeats attributes in part to lagging review processes on major aggregation platforms such as DexScreener. These platforms often populate "official website" and social links directly from a token's metadata—fields that can be changed by the token creator or by parties claiming they have "taken over" the community. Attackers are exploiting this gap to turn meme-coin listing pages into new phishing grounds.
BlockBeats warned that clicking unfamiliar links is often unavoidable during on-chain scans. If a "Cloudflare verification" page or any similarly suspicious prompt appears, users should close it immediately and avoid any interaction to protect their assets.