Criticalscore 100 · flagged Thursday, September 3, 2026

walletcloudflare.com

Appeared in the .com zone on Thursday, September 3, 2026; by the end of that day the census found active website about crypto web3. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: cloudflare
+30
lure words (login, verify, secure…)
matched: wallet
+26
brand name at a retail registrar
matched: HOSTINGER operations, UAB
+8
brand name at a watch-list registrar
matched: HOSTINGER operations, UAB
+6
brand name and brand-styled page
matched: cloudflare
+15
form on a brand-styled page
matched: has_form
+18
Registrar
HOSTINGER operations, UAB
Nameserver provider
Nameservers
apollo.dns-parking.com, athena.dns-parking.com
First-day state
active website
HTTP status
200
Page title
Cloudflare Wallet — Reserve your name
Has a form
yes
Brand echoed
cloudflare

Model opinions

Second opinionlooks like phishingtarget: Cloudflareconfidence 92%· claude-opus-5

Domain registered at Hostinger with parking nameservers renders a full Cloudflare-branded page (orange cloud logo, 'Cloudflare Wallet — Reserve your name', fake yourname.cloudflare.pay handle) with a reservation form posting to itself, decoy links to blog.cloudflare.com and a Telegram operator contact — a fake Cloudflare crypto-wallet 'reservation' front collecting handles/personal data, not any Cloudflare property.

First passlooks like phishingtarget: Cloudflareconfidence 95%· claude-haiku-4-5

The domain walletcloudflare.com uses Cloudflare's logo, branding, and product name ('Cloudflare Wallet') to impersonate an official Cloudflare service. The page contains a form posting to itself with a text input field for 'yourname', combined with a Telegram operator contact link, matching the sealed-room phishing pattern designed to harvest names or credentials under the guise of reserving a wallet handle for a non-existent Cloudflare service.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Thursday, September 3, 2026

Screenshot of walletcloudflare.com taken by the zone census on 2026-09-03

Same data as JSON: /api/zone/domain/walletcloudflare.com. This page is not indexed by search engines and does not link to the site it describes.