The author discovered what appeared to be a sophisticated consent phishing attack targeting Cloudflare users, using a cloudflare.pay domain to mimic a legitimate handle-claiming feature. Upon closer inspection, it turned out to be Cloudflare's own feature with poor security UX — the .pay TLD domain, misleading authorization page, and spoofable green checkmark all raised red flags typical of OAuth consent phishing.
Background
OAuth consent phishing has become a popular attack vector where attackers register lookalike domains to trick users into granting malicious app permissions. The .pay TLD is a relatively unrestricted domain extension that requires only $20 to register, unlike more vetted TLDs like .bank.
- Source
- Lobsters
- Published
- Aug 5, 2026 at 02:31 AM
- Score
- 7.0 / 10