Google-Style Phishing Emails Target Crypto Traders With Hidden Account Theft Links

Google-Style Phishing Emails Target Crypto Traders With Hidden Account Theft Links

N
News Editor 01
2026-07-23 09:00:15
Crypto users are warning about phishing emails that mimic real Google account alerts. The messages hide malicious links inside recovery request details and can steal passwords, session data, or wallet access.
crypto securityphishing emailsGoogleexchangeswallet security

Crypto users are flagging a phishing campaign that makes scam emails look like legitimate Google account notices. Reports say attackers are using recovery contact request emails and placing a malicious link inside the request details, making the message appear safer than a typical scam. At a glance, it can look routine. The harmful part sits lower in the email.

Attackers lean on familiar Google security formatting

The method stands out because it does not rely on a crude fake sender alone. Instead, the email is designed to resemble a genuine Google account alert, using wording such as “recovery contact request” or “review request.” That visible trust layer can lower suspicion, especially for users who are used to frequent account notifications.

Reported screenshots showed those labels, but users are being warned not to treat them as proof that the request is authentic. If the check stops at the subject line or the top section of the message, the scam can be easy to miss.

Hidden links can lead to exchange logins and wallet approvals

According to the report, the phishing emails use spacing tricks to push malicious content far below the visible portion of the message. The upper part can resemble a standard Google security email, while the dangerous link is placed farther down. That layout matters. It helps the email pass an initial visual check.

For crypto users, the main threat is account takeover. A fake login page can capture passwords, session data, or two-factor prompts. If attackers gain entry to an exchange account or intercept a wallet approval flow, funds can be moved quickly. The risk spans both exchange users and DeFi participants.

Phishing and social engineering remain a major crypto risk

Recent crypto.news coverage adds context. Binance said its systems blocked 22.9 million scam and phishing attempts in Q1 2026, a 54% increase from the previous quarter. The exchange said those controls protected about $1.98 billion in user funds. Another related effort is Ethereum’s ERC-7730 Clear Signing standard, which is meant to make wallet approvals easier to read as phishing and approval scams continue to outnumber many protocol-level hacks.

The broader threat is still active. crypto.news also reported that Coinbase, Microsoft, and Europol helped dismantle the Tycoon 2FA phishing network, which Europol said had been generating tens of millions of phishing emails each month. The scale is large, and the tactic is far from isolated.

Users are being told to verify requests inside official accounts

Google’s account help guidance says users should review recent security events from their Google Account instead of trusting suspicious prompts in email. It also advises checking unfamiliar devices and enabling 2-Step Verification to reduce the risk of account takeover. Google warns that fake security emails may ask for passwords or personal data.

The same practice applies to crypto accounts and wallets. Users should open the official app or website directly, verify alerts from inside the account, and avoid entering seed phrases on any page reached through an email prompt. Google also says it never asks for passwords or verification codes over email, phone calls, or messages.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.