On May 25, 2026, on-chain analyst b-block posted a warning on X: fake Uniswap Google ads have stolen at least $400,000 from crypto users. Two attacker wallet addresses were confirmed on Etherscan, holding 146 ETH (~$306,000) at the time of reporting.
The scam is brutally simple. Users who click a sponsored Google ad for Uniswap land on a convincing clone site. Connecting their wallet and signing a single transaction grants attackers full control to drain assets. The wallet drainer tool used is called AngelFerno, a scam-as-a-service script targeting DeFi users. Attackers deploy multiple domains, some using Cyrillic characters (Punycode URLs) to visually mimic legitimate addresses.
SEAL: $1.27M Stolen in Three Weeks, Uniswap Most Impersonated
The Security Alliance (SEAL) reported that malicious Google ad campaigns stole more than $1.27 million between March 13 and 30, 2026 alone. One single theft in early March reached $385,000. SEAL has blocked over 356 malicious ad links in the past year and warns the campaign remains active.
Platforms impersonated include Uniswap, PancakeSwap, Morpho Finance, Hyperliquid, CoW Swap, and Ledger. Uniswap accounts for 41% of all detected fake sites, followed by Morpho Finance at 31%. Separately, attackers in early May abused Google Ads alongside shared chats with AI chatbot Claude in a malvertising campaign targeting Mac users. Facebook is also used for fake ads, with scammers creating near-perfect clones of the Windows 11 download page to deploy crypto-stealing malware.
Experts Blame Google for Long-Standing Vulnerabilities
Stacy Muur, founder of Web3 marketing agency Green Dots, called the situation unacceptable: “Google has ignored this for years. Fake links keep appearing above real ones.” In July 2025, a DeFi user lost $1.2 million through an identical Uniswap Google ad scam. Forensic investigator ZachXBT publicly demanded severe consequences for Google. DeFiLlama confirmed that fake ads on Google are a common source of phishing and recommended domain verification tools.
Security experts advise five immediate steps: 1) Never click sponsored results for crypto platforms; bookmark the real URL. 2) Scrutinize the URL for Cyrillic characters or extra hyphens. 3) Use phishing blockers like ScamSniffer or Wallet Guard. 4) Do not approve any transaction you didn't initiate. 5) Regularly revoke unused approvals using revoke.cash.

