Sony's Soneium Blockchain Project Targeted by Google Ad Phishing Scam

Sony's Soneium Blockchain Project Targeted by Google Ad Phishing Scam

N
News Editor 01
2026-07-06 14:13:58
Scam Sniffer exposed a phishing scam targeting Sony's Soneium blockchain project via Google ads, redirecting users to a fake website acting as a wallet drainer, stealing crypto from connected wallets.

近日,索尼旗下的区块链项目Soneium成为网络钓鱼诈骗的新目标。知名Web3反诈平台Scam Sniffer揭露,攻击者利用Google广告系统投放虚假广告,将搜索“Soneium”的用户引导至一个与官方网站高度相似的钓鱼页面。该页面实为“钱包盗取器”,一旦用户连接钱包,加密资产将被迅速转走。

诈骗手法:广告诱导与界面仿冒

根据Scam Sniffer在X平台发布的帖子,当用户在Google搜索Soneium时,一条付费广告会出现在搜索结果顶部。点击该广告后,用户会被重定向到一个域名与官方极其相似的网站(例如“soneium”被拼写为“someium”)。钓鱼网站完全复制了Soneium官网的页面设计、Logo和布局,普通用户几乎无法分辨真伪。Scam Sniffer强调:“疏忽大意时钓鱼总是会发生,即便你只是把‘soneium’误拼成‘someium’。

技术手段:绕过Google安全审核

Scam Sniffer分析指出,攻击者采用了复杂的技术手法来规避Google的广告审核机制。这些手法可能包括URL重定向、页面伪装或利用Google Ads的合规漏洞。一旦用户连接MetaMask或其他Web3钱包,钓鱼网站便会自动发起恶意合约交互,授权转移用户的ERC-20代币或NFT。Scam Sniffer此前曾多次曝光类似利用搜索引擎广告进行资产盗取的事件,此次涉及索尼背书的主流项目,再次凸显了加密行业安全威胁的严峻性

影响及防范建议

尽管Soneium尚未正式上线主网,但该项目凭借索尼的品牌效应吸引了大量关注。此次钓鱼事件可能导致部分早期用户蒙受损失,并对项目声誉造成负面影响。专家建议用户:

1. 直接输入官方网址,避免通过搜索引擎广告访问项目网站;
2. 仔细核对域名拼写,注意是否存在细微差异;
3. 不要轻易连接钱包到陌生页面,尤其警惕要求签名授权的弹窗;
4. 使用硬件钱包或设置多签授权以降低风险。

截至发稿时,Google尚未就此事件公开回应,但用户反馈相关钓鱼广告已被部分下架。Scam Sniffer提醒社区持续保持警惕,因为类似的攻击模式可能会在更多热门项目上重演。

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.