Security researchers and onchain analysts have flagged a phishing campaign in which fake websites posing as Uniswap were promoted through Google Search ads, leading to at least $400,000 in confirmed losses. Onchain analyst b-block said the spoofed pages were draining funds from multiple wallets, while Green Dots co-founder Stacy Muur said the thefts were tied to paid search ads that appeared ahead of legitimate results.
According to the report, the attackers either bought ads directly or compromised legitimate advertising accounts to place malicious links in Google’s sponsored search section. These ads were designed to look trustworthy and to outrank the real protocol pages. Etherscan data cited in the story showed two flagged addresses holding a combined 146 ETH, valued at about $306,000, while the overall confirmed theft linked to the campaign was reported at no less than $400,000.
Search-based phishing surged in March
Security Alliance, or SEAL, said in an April report that crypto phishing on Google Search rose sharply in March. The group said attackers disguised their ads as popular crypto protocols, used seemingly normal URLs to avoid automated review, and embedded hidden iframes that loaded malicious code outside the view of Google’s detection systems.
When users clicked through, they were taken to convincing copies of real crypto apps, but their traffic was secretly routed to servers controlled by the attackers. SEAL estimated that between March 13 and March 30, this broader wave of Google Search phishing led to $1.27 million in stolen funds. By the time the report was published, the organization said it had blocked more than 356 malicious ad links and warned that the campaign showed no sign of slowing.
The problem goes beyond crypto
The report also noted that fake ads are spreading into other sectors. Recent cases have involved malicious software distributed through Google ads, as well as fraudulent Facebook promotions imitating official download pages to steal credentials and crypto assets. For crypto users, the takeaway is straightforward: paid search results should not be treated as automatically trustworthy, and checking the exact domain before connecting a wallet or signing any transaction remains a basic but critical defense.

