Safety researchers say Google’s advert platform has been weaponized for over a 12 months, with risk actors working pretend sponsored hyperlinks that funnel unsuspecting crypto customers to phishing websites designed to empty their wallets.
How The Assault Works
The scheme targets folks trying to find Uniswap, the decentralized trade, by inserting fraudulent adverts above the respectable web site in Google’s sponsored outcomes part.
Attackers both buy advert house outright or break into current advertiser accounts to run the pretend listings, then outbid the true protocol to safe the highest place.
What makes the adverts onerous to catch is how they’re constructed. The phishing hyperlinks use URLs that look genuine, whereas a hidden secondary aspect quietly hundreds the malicious code — invisible to Google’s automated overview techniques.
Victims who click on by land on convincing replicas of the true Uniswap platform, with all their community exercise routed silently by attacker-controlled servers.
Group alert:
A web site impersonating Uniswap is draining funds from a number of wallets.
The scammers are at present holding at the very least ~$400,000.
0x37925684BA178821b4436E06e67f5dBD6cfA49Bb
0x2fC25F46cC49D226eF92E9A7665f3d2821F3c5E2Please solely use official hyperlinks, and… pic.twitter.com/JikqftTVHY
— b-block (@b_block_oficial) Could 25, 2026
On-chain analyst “b-block” raised the alarm on Monday after tracing stolen funds to addresses linked to the pretend Uniswap web site.
On the time of writing, two flagged wallets held a mixed 146 ETH, valued at roughly $306,000. The entire haul is estimated at at the very least $400,000.
A Yr Of Losses
The nonprofit Safety Alliance, often called SEAL, has been monitoring the broader sample. In line with the group, there was a pointy rise in such a phishing exercise in March, with $1.27 million stolen between March 13 and 30 alone.
SEAL stated it blocked greater than 356 malicious advert hyperlinks, describing that quantity as typical of weekly attacker exercise sustained for greater than a 12 months — and stated the tempo has not slowed.
Stacy Muur, founding father of Web3 advertising company Inexperienced Dots, shared a screenshot of 1 such sponsored consequence and stated scammers had used it to steal funds from customers. She referred to as out Google straight, saying the corporate has let the issue persist for years whereas customers proceed to lose cash.
DeFiLlama, a crypto knowledge platform, echoed the priority, calling pretend Google adverts a standard and recurring supply of phishing assaults concentrating on the crypto group.
Two scammers have already stolen ~$400,000 from customers by a phishing @Uniswap advert on Google.
It’s insane that Google has ignored this situation for years whereas pretend hyperlinks preserve getting pushed above actual ones and customers preserve getting drained.
That is the primary consequence that popped out… pic.twitter.com/qStRGq8qTE
— Stacy Muur (@stacy_muur) Could 25, 2026
The Menace Spreads Past Google
The Uniswap case is a part of a wider sample hitting a number of platforms and audiences. Reviews point out that in early Could, attackers had been abusing each Google Ads and shared chat hyperlinks from AI instruments to push malware concentrating on Mac customers in an lively marketing campaign.
In the meantime, experiences observe that Fb has seen an analogous wave of faux paid adverts, with scammers mimicking official Microsoft promotions and directing customers to counterfeit Home windows 11 obtain pages loaded with credential-stealing malware.
SEAL stated it continues to obtain experiences from victims and that the marketing campaign reveals no signal of stopping.
Featured picture from Unsplash, chart from TradingView
Editorial Course of for bitcoinist is centered on delivering totally researched, correct, and unbiased content material. We uphold strict sourcing requirements, and every web page undergoes diligent overview by our staff of prime expertise consultants and seasoned editors. This course of ensures the integrity, relevance, and worth of our content material for our readers.


