IOC Check
zsowopro.coinbsde.com domain Malicious 7/10
Threat Types
Crypto Phishing Brand Impersonation DGA Infrastructure
Misteye Analysis
2 / 94Engine Flagged
CoinbaseImpersonated Brand
2025-08-08Domain Registered
Related IOCs
coinbsde.com 824971-kraken.com krakenapp.vip airdrop-wlfi.app zama-voting.com
Recommended Actions
1Block *.coinbsde.com at DNS gateway, firewall, and proxy servers immediately
2Scan email logs for phishing messages containing this domain
3Check endpoint DNS/HTTP logs for historical connections to this domain
4Expand threat hunting to all 19 associated phishing domains (Kraken, WLFI, Zama)
Claude
OpenAI
Gemini
Consensus: High
Paste Solidity code or upload a .sol file
pragma solidity ^0.8.0;
contract Vault {
mapping(address => uint256) public balances;
function withdraw() public {
uint256 amount = balances[msg.sender];
(bool success, ) = msg.sender.call{value: amount}("");
require(success);
balances[msg.sender] = 0;
HIGH Reentrancy Attack 3/3 models Claude OpenAI Gemini

withdraw() transfers ETH before clearing the balance, allowing an attacker to re-enter via fallback and drain funds repeatedly.

msg.sender.call{value: amount}("")
MEDIUM Missing Zero-Address Check 2/3 models Claude Gemini

The withdraw function does not verify msg.sender is a non-zero address. While rare, a zero-address call could lock funds permanently.

balances[msg.sender] = 0;
Attack Analysis Report BSC (Chain 56) 12 rounds
Vulnerability Root Cause

Reentrancy via Vulnerable Proxy — VaultProxy did not implement nonReentrant modifier, allowing recursive calls during withdrawAll() execution.

Attack Path
1Attacker flash-borrows 10,000 WETH from Aave V3
2Executes deposit() to initialize victim vault position
3Triggers withdrawAll() which lacks state-lock protection
Profit Analysis
500.00 ETHTotal Stolen (WETH/WBNB)
0.42 ETHGas Cost (Total Txs)
499.58 ETHNet Profit
Fix Recommendations
Implement ReentrancyGuard on all external call functions
Use Checks-Effects-Interactions pattern for all state changes