August 4, 2026

Phishy business, very real drama

Security Is Hard, Y'all

Cloudflare’s shiny new feature looked so shady, commenters called it a scam in a trench coat

TLDR: Cloudflare launched a real new feature that looked so suspicious even a careful user — and Cloudflare’s own chat bot — thought it was a scam. Commenters piled on, arguing the bigger story is not that online safety is hard, but that this launch was confusing enough to destroy trust.

A supposedly exciting new Cloudflare feature turned into a full-on "is this real or am I being robbed?" moment — and the comments absolutely feasted. The author rushed to claim a username, hit a permission screen on a totally different web address, saw a suspicious green check, and did what many cautious internet users would do: assumed the whole thing was a phishing trap. Plot twist: it was real. Even bigger plot twist: Cloudflare’s own chat bot reportedly said the product didn’t exist and warned it might be a scam. That detail sent readers into orbit.

The loudest reaction was brutal: this wasn’t "security is hard," commenters argued, it was Cloudflare fumbling the basics. One person flatly called the company "pretty incompetent," while others mocked the classic corporate move of launching a new product in a way that looks exactly like fraud. The biggest gripe? If you’re a major company, why send people to a weird new address instead of your normal site where trust already exists? To many readers, that alone made this feel less like a product launch and more like a prank.

But there was also delicious side-eye aimed at the author. Some commenters joked this was a fanboy reality check, while others said the screenshot looked obviously fake from the jump. And the AI bot getting the answer wrong? That became the comic relief and the horror story at once: why add a helpful assistant, people asked, if it confidently panics before the users do?

Key Points

  • The article describes a legitimate new Cloudflare product flow that initially appeared to be a phishing attempt.
  • A major source of suspicion was that the product used the cloudflare.pay domain rather than a path or subdomain on cloudflare.com.
  • The author found no Wallet entry in the Cloudflare dashboard or documentation, and Cloudflare’s AI chat agent also indicated the product should be treated as phishing.
  • Further investigation showed that the Wallet site and authorization flow were legitimate, and the suspicious green checkmark was a security UI element.
  • The article concludes by urging developers to host new apps under trusted domains and display security information clearly when users must make security decisions.

Hottest takes

"cloudflare is pretty incompetent" — 63stack
"indistinguishable from a phishing attack" — Joker_vD
"Today my fanboy bubble was burst" — thataccount
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.
Security Is Hard, Y'all - Weaving News | Weaving News