Skip to main content
Sign in

Fake Chainbase Airdrop Phishing Campaign

avoid.net/fake-chainbase-airdrop-phishing-campaign2/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·2PGJdy…WXgv

Summary

An ongoing phishing campaign, active since at least July 2025, impersonates Chainbase — a legitimate Singapore-based Web3 data infrastructure company — to lure cryptocurrency holders into either granting unlimited wallet spend approvals or surrendering seed phrases via fake 'wallet update' forms. The campaign exploits the timing of Chainbase's real $C token airdrop (launched July 14, 2025 on airdrop.chainbase.com) and operates through dozens of rotating domains anchored by chainbz[.]vip, using stolen branding, malicious ads, and social media spam. Chainbase has not authorized any third-party claim sites; all legitimate claims occurred exclusively at airdrop.chainbase.com.

Have evidence about Fake Chainbase Airdrop Phishing Campaign?

Timeline(6 events)

6 July 2025

Binance HODLer Airdrop snapshot window opens for Chainbase $C token (July 6–9, 2025); attacker infrastructure likely deployed around this period to capitalize on high user interest.

Binance Square post (Chainbase HODLer Airdrop announcement)

14 July 2025

Official Chainbase Airdrop Season 1 launches at airdrop.chainbase.com; Chainbase blog explicitly warns users that all claims occur only on the official domain and to beware impersonators.

Chainbase Official Blog

18 July 2025

Binance lists Chainbase $C token with spot trading pairs (C/USDT, C/BNB, C/USDC); $C surges over 230% in 24 hours, significantly raising public profile of Chainbase and likely expanding the phishing campaign's target pool.

Binance HODLer Airdrop post; CryptoNinjas reporting

29 July 2025

PCrisk publishes removal guide for the Chainbase Airdrop Scam, documenting chainbz[.]vip as the primary phishing domain, serving IP 104.21.80.1, and the two-stage attack methodology (wallet approval and seed phrase harvesting).

PCrisk

30 July 2025

MalwareTips publishes analysis of the campaign, adding additional confirmed phishing domains: chainbase-airdrop[.]org and chainbasedrops[.]xyz, and noting that domains change frequently.

MalwareTips

31 July 2025

CyberInsider publishes report on the phishing campaign, summarizing attack mechanics, distribution vectors, and the use of fake sponsored ads and social media impersonation accounts.

CyberInsider
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 12 of 12 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 6/2/2026, 8:11:51 PM

last updated: 7/26/2026, 4:25:40 PM

avoid.net — verified advice for a post-truth world