
A sophisticated phishing operation using fake Uniswap advertisements on Google has successfully drained cryptocurrency from multiple wallets, with on-chain investigator b-block reporting that two attacker addresses now hold approximately $400,000 in stolen crypto. The fraudulent ads redirect users to clone websites that drain wallets upon connection, with the attackers currently holding 146 ETH (approximately $306,000) across the flagged addresses. Researcher Stacy Muur highlighted the persistence of this issue, noting that such phishing ads have been promoted to the top of search results for years, often appearing above official cryptocurrency project links. As per DefiLlama, fake ads on Google remain one of the most common attack vectors in the decentralized finance sector, prompting the development of LlamaSearch with thousands of vetted crypto domains to address this security gap.
The phishing incident represents a continuation of ongoing security concerns in the decentralized finance sector. As reported by b-block, analysts have been raising warnings about phishing websites for months, with Hayden Adams publicly criticizing these scams in February, stating that "these scams are horrible, we've been fighting them for years." Adams specifically noted that fraudulent apps impersonating Uniswap circulated while the company waited months for approval on Apple's App Store, and that scam advertisements continued to reappear despite ongoing reporting efforts. Fake interfaces have become one of the most common phishing vectors in DeFi, where scammers purchase search ads and register lookalike domains that mirror official front-ends, then prompt users to sign malicious approvals.
Security Alliance (SEAL) specialists have documented a significant surge in similar phishing activities, reporting that over 356 malicious ad links were blocked from March 13-30, with total damage from the campaign amounting to approximately $1.27 million. According to SEAL, the perpetrators use either direct ad purchases or compromised advertiser accounts for promotion, bypassing Google's moderation systems by displaying correct URLs while malicious code is loaded through hidden frames invisible to automated verification systems. This latest Uniswap attack demonstrates the continued effectiveness of these sophisticated phishing techniques in the cryptocurrency space, where attackers often outbid legitimate companies to help phishing pages rise to the top of sponsored search results.
The Uniswap attack occurs against a backdrop of significant cryptocurrency fraud activity. According to the FBI's 2025 Internet Crime Report, there were 181,565 cryptocurrency-related complaints totaling $11.36 billion in losses, representing a 22% increase from 2024. The average crypto fraud victim lost $62,604, with crypto-linked phishing and spoofing alone producing 7,164 complaints and more than $111 million in reported losses. Data from blockchain security firm Scam Sniffer also showed that signature phishing attacks siphoned $6.27 million from crypto wallets during the first month of the year, with earlier incidents including a user losing more than $1.23 million in Uniswap NFTs through a fake site and fake Aave advertisements appearing in Google search results.
The incident underscores the critical importance of security protocols in the crypto space, particularly regarding platform authentication and URL verification. Standard guidance from security firms emphasizes revoking unused token approvals, verifying URLs, and avoiding clicking sponsored search results when interacting with DeFi protocols. The warning comes as part of ongoing efforts to educate users about the prevalence of phishing attacks in the DeFi ecosystem, where users must remain vigilant about the authenticity of websites and transaction requests to protect their assets. BeInCrypto has approached both Uniswap and Google for comment on the incident, highlighting the need for platform-level responses to address these persistent security challenges. The latest incident shows how closely crypto security now overlaps with search visibility, ad placement, and brand impersonation, with the attack surface beginning before users even reach applications through search engine results.