
A malicious website impersonating decentralized exchange Uniswap has successfully drained multiple wallets and accumulated at least $400,000 in stolen assets. According to on-chain analyst 'b-block', the attackers used phishing pages that closely copied Uniswap's interface and tricked victims into approving unlimited asset transfers through malicious smart contracts. As reported by Scam Sniffer, these fraudulent websites prompt users to approve transactions that hand wallet access directly to attackers. The campaign represents a sophisticated operation that leveraged Google's advertising platform to target unsuspecting users, with victims clicking paid ads believing they were official links. Stacy Muur, founder of Web3 marketing agency Green Dots, shared definitive proof of the active exploit, calling out the search engine's advertising infrastructure for long-standing consumer vulnerabilities: "It's insane that Google has ignored this issue for years while fake links keep getting pushed above real ones and users keep getting drained."
The analyst shared two wallet addresses tied to the operation, which together held 146 ETH worth approximately $306,000 at the time of reporting, based on Etherscan data. According to Scam Sniffer, the attackers used a phishing page that closely copied Uniswap's interface and tricked the victim into approving unlimited asset transfers through a malicious smart contract. The malicious websites prompted users to approve transactions that handed wallet access directly to attackers. Security Alliance (SEAL) reported that similar campaigns stole $1.27 million in total between March 13 and March 30 alone, demonstrating the widespread impact of these Google-based phishing operations. In one separate reported case, a user lost more than $1.23 million in Uniswap V3 NFTs after interacting with a phishing website promoted through Google Ads. The warning highlights a broader rise in crypto phishing campaigns, with Security Alliance reporting a sharp increase since March. Muur criticized Google for ignoring this issue for years, stating "It's insane that Google has ignored this issue for years while fake links keep getting pushed above real ones and users keep getting drained."
Blockchain security firms have warned that attackers increasingly rely on Punycode domains and cloned interfaces that look nearly identical to legitimate crypto platforms. According to SEAL, all traffic from those cloned platforms gets routed through attacker-controlled servers that can intercept approvals and drain wallets. The latest campaign used a sophisticated approach where attackers deployed paid sponsored results to direct victims to near-perfect clones of Uniswap's interface. As reported by SEAL and analytics firm DeFiLlama, the attackers used legitimate-looking URLs to pass automated checks and loaded a hidden secondary iframe that delivered the malicious code. Once users connect wallets and approve transactions, scammers gain direct access to assets without needing private keys. SEAL explained that victims land on convincing clones of real crypto apps, with all network traffic secretly routed through attacker-controlled servers. Researchers also noted that attackers increasingly use Punycode-style web addresses that closely resemble legitimate crypto domains, making fake sites harder to detect during casual browsing.
Security groups have documented a significant uptick in Google-based phishing operations, with SEAL blocking more than 356 malicious advertisement links in March alone. According to Stacy Muur, the issue has persisted for years as fake links continue to appear above legitimate results. SEAL reports that attackers either pay the ad platform directly, compromise legitimate advertiser accounts, or outbid legitimate exchanges to secure top placement in sponsored results. The crypto non-profit group Security Alliance (SEAL) reported in April that there was a "significant uptick" in phishing activity on Google search in March, with the campaign showing no signs of slowing down. SEAL added that the blocked links represent "a steady volume of attacker-deployed Google Ads each week for more than a year," with the organization receiving more reports from affected users. Google's practice of placing sponsored links above organic results increases the visibility of fraudulent ads, making them more effective at targeting unsuspecting users. Analytics platform DeFiLlama confirmed that fake ads on Google are a common source of phishing attacks, with researchers pointing users to tools designed to verify legitimate crypto domains and reduce exposure to fraudulent websites. Additionally, earlier this month, a malicious ad campaign targeting Mac users emerged, leveraging Google ads and shared chats with the AI chatbot Claude, while Malwarebytes also reported that Facebook remains a major hub for fake ads and scams.