Analysis of the domain bitmartloggine.webflow.io indicates a high-risk phishing infrastructure targeting users of the BitMart cryptocurrency exchange. The domain is currently active as of July 31, 2026, and resolves to the IP address 172.64.151.8, which is associated with Webflow's hosting infrastructure. Notably, the domain lacks configured nameservers, a technical anomaly that often accompanies hastily deployed phishing sites or domains intended to evade detection through unconventional DNS configurations. Registration details confirm the domain was created through Webflow, Inc., a legitimate platform frequently exploited by threat actors to host fraudulent pages due to its ease of use and free tier offerings.
The domain appears on at least one security blocklist, and six out of ninety-one security vendors on VirusTotal have flagged it as malicious, providing concrete evidence of its use in phishing operations. While the exact content of the site has not been analyzed, the domain name explicitly references 'bitmartloggine,' strongly suggesting an intent to impersonate BitMart's login portal to harvest credentials. The absence of nameservers does not prevent the site from remaining operational, as Webflow's hosting infrastructure may still serve content directly via its IP address or through alternative resolution paths. Defenders should treat this domain as an active threat.
Network-level blocking of the IP 172.64.151.8 and the domain itself is recommended to prevent user exposure. Organizations should also monitor for any attempts to access this domain from internal networks, as such activity may indicate compromised credentials or ongoing phishing campaigns targeting employees or customers. Given the domain's registration through Webflow, security teams may consider reviewing other domains hosted on the same platform or IP range for additional phishing activity.