Analysis of coinbase-extension-wallet.blogspot.com as of July 30 2026 indicates that the domain is actively used in a crypto‑drainer campaign. The domain resolves to the public IP address 142.251.14.132, which is shared with other Google‑owned services and does not appear to be a dedicated malicious host. Registration data shows the domain was created through Google LLC, and the nameserver information is currently unavailable (NS_NOT_FOUND), suggesting that standard DNS records have not been published or are being concealed. VirusTotal has recorded detections from seven out of ninety‑one scanned security vendors, confirming that multiple independent engines have identified malicious behaviour associated with the domain.
In addition, the domain is listed on three external security blocklists, and it has been explicitly blocked by the PhishDestroy, MetaMask, and SEAL filtering solutions, all of which flag it as a crypto‑drainer threat. No public Safe Browsing, OTX, SSL certificate, HTTP status, or page‑title information has been released, so the visual or content characteristics of the site remain unverified. The available evidence points to a persistent infrastructure that leverages a legitimate blogging platform to host malicious payloads or redirect victims to credential‑stealing services.
Defenders should continue to deny network resolution to 142.251.14.132 for endpoints that do not require Google services, enforce URL filtering rules that include the domain and its known blocklist identifiers, and monitor for any newly observed subdomains or variants that reuse the “coinbase‑extension‑wallet” naming pattern. Endpoint protection products that integrate the PhishDestroy, MetaMask, or SEAL blocklists are already configured to block access, but organizations should verify that these signatures are up‑to‑date.