Fake Crypto Login Pages Trigger Phishing Alerts as FMA Flags Malicious Domains
Multiple phishing domains mimicking the login page of Blockchain.com have been flagged by New Zealand’s Financial Markets Authority (FMA), following reports that users have been tricked into entering their credentials via fraudulent search-engine advertisements.
The FMA has listed several domains—including blokchain.co.com, blockchain.metafina.co.com, blockchain.spinuza.cc, and blockchain.scifin.eu.com—as active phishing websites as of August 6, 2025. These sites were reportedly promoted through paid search ads, often appearing as the top results when users searched for “Blockchain” or “Blockchain.com.”
Instead of directing users to the legitimate platform, these advertisements reroute them to lookalike login pages designed to harvest credentials. Once login details are entered, attackers reportedly use them to access users' real Blockchain.com accounts.
The incident highlights the persistent risks facing search-based traffic acquisition and the vulnerabilities that arise when fake domains exploit advertisement placements. Unlike more sophisticated software exploits, these phishing schemes rely entirely on front-end deception through impersonation and paid visibility.
Firms that operate cryptocurrency platforms or digital wallet services are advised to monitor the misuse of their branding in paid ad networks. There is no indication from the FMA that Blockchain.com itself has been compromised.
Financial service providers may need to reassess their brand protection mechanisms and ad monitoring policies, particularly around keywords linked to login activity. Meanwhile, users are advised to avoid clicking on search result ads and to enter known URLs directly into their browsers.
Subscribe Now

