MALICIOUS — CRITICAL
coinbase-event[.]fun
This domain, coinbase-event.fun, poses a high-risk threat as a fraudulent crypto airdrop platform impersonating Coinbase.
- VirusTotal
- 19/93
- Blocklists
- No stored match
- Disponibilidad
- Contenido no disponible · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
coinbase-event.fun — Contenido no disponible (HTTP 502). Suplantación de marca: Coinbase; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 19/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
This domain, coinbase-event.fun, poses a high-risk threat as a fraudulent crypto airdrop platform impersonating Coinbase. The site lures victims with promises of free cryptocurrency distributions, a common tactic to harvest wallet credentials or deploy malicious smart contracts. Users who interact with the site risk unauthorized access to their digital assets, financial loss, or exposure of sensitive account information. The fraudulent nature is reinforced by the site's design, which mimics legitimate Coinbase branding to deceive targets into believing the offer is authentic. Analysis indicates this domain was registered on February 21, 2026, and is hosted on Cloudflare infrastructure at IP address 104.21.76.121. It has been flagged by 19 out of 95 security vendors on VirusTotal, confirming its malicious classification. The domain appears on three security blocklists and uses a WE1 SSL certificate, a low-assurance certificate often associated with short-lived phishing campaigns. The page title, 'Coinbase Coin | Airdrop,' directly references Coinbase branding, further solidifying its intent to impersonate the legitimate exchange. If you visited coinbase-event.fun or interacted with its content, immediate action is required. Disconnect any connected wallets or devices from the internet to prevent ongoing malicious activity. Review all recent transactions for unauthorized transfers and revoke any suspicious smart contract approvals. Change passwords for associated accounts, enable multi-factor authentication, and monitor financial statements for unusual activity. Report the incident to relevant security teams and consider freezing compromised assets if theft is suspected. Users should also scan their devices for malware, as phishing sites may deliver secondary payloads.
Cobertura de los datos12 recorded checks
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.