Security Scan Report: coinbaseverify.vercel.app

Site favicon
Submitted: Sep 23, 2026, 8:51:42 AMCompleted: Sep 23, 2026, 8:52:21 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Phishing page impersonating Coinbase on a free vercel.app subdomain, harvesting account credentials and a 12-word wallet passphrase. Do not enter any data.

Risk Factors
Brand impersonation of Coinbase on a non-official domain (coinbaseverify.vercel.app)
Credential harvesting form (email + password) styled as the Coinbase sign-in page
Seed-phrase (12-word passphrase) collection 'Unlock Wallet' flow — cryptocurrency drainer pattern
Free shared-hosting subdomain with unknown creation date
Unranked domain not present in Cisco Umbrella top 1M
IDS alerts referencing the abused cloud hosting service domain vercel.app
Domain age information unavailable

Details

Page Title

Coinbase - Sign In

Scan Type

public

Domain Name Analysis

Domain 'coinbaseverify.vercel.app' uses the application-focused generic top-level domain (.app) with subdomain 'coinbaseverify'. The registrable portion 'vercel' spans 6 characters holding 2 vowels versus 4 consonants. Word splitting yields 2 words: ver, cel. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://coinbaseverify.vercel.app/

Page Load Overview

0.66s
Total Load Time
145 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:285 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency blockchain50% confidence
Type: webapp
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
50%
finance banking
38%
e-commerce shopping
29%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
764.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
6216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
132--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16D2264B22421473B9797D7B472B0BF95DC9EC31ADD77880AE6ED41A617D0CB1CA02A02

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:TJSfAlq1AEhHf3zoNeSyuyirywbEgoEcF4Q7YVrZAr8YRoQyBaX17XqJw/Wls7SN:sfAlq1f5fXPi254uzYVrmrjpanforU

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10458:0AhhQA0UIGmiCQCQIBAgAIKhAsGFFQCERAwHUyhEkvUFCwKMACRaIB3Q5FIASFCIEORpHOkAgCURSIAKCUBSFAMAIEAgQiKE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e0f8f8d818181000
Perceptual Hash:dcc3338d26729999
Difference Hash:083030303232320c
Wavelet Hash:fcfcf8f8f8981800
Color Hash:#9653ac

Other Hashes

Crop Resistant:083030303232320c

Scan History

Scan history not available

Unable to load historical scan data