TLDR
- Fake Uniswap Google ads directed users to phishing pages that drained connected crypto wallets online.
- On-chain analyst b-block said two scammers held assets worth more than $400,000 after thefts occurred.
- Etherscan data showed two flagged addresses together held about 146 ETH, worth roughly $306,000 there.
- SEAL reported search phishing grew in March, while attackers used deceptive ads and hidden iframes.
- DeFiLlama and Malwarebytes warned that fake ads remain a common route for crypto scams online.
A fake Uniswap website has stolen more than $400,000 from several crypto wallets, according to on-chain reports. The phishing site appeared through sponsored Google search results and copied the trusted Uniswap brand. The case has renewed concern over fake crypto ads on search engines and social platforms.
Fake Uniswap Ads Lead Users to Phishing Site
On-chain analyst “b-block” posted that two scammers drained wallets through a counterfeit Uniswap website. The analyst said the attackers held more than $400,000 in assets after the reported thefts. The post said the scam reached users through a paid Google search ad.
Etherscan data showed two flagged addresses holding about 146 ETH at the time of reporting. That amount was worth nearly $306,000, based on figures cited in the report. The total may change because wallet balances can move quickly across different addresses.
Stacy Muur, founder of Web3 marketing agency Green Dots, shared screenshots of fake sponsored results. She criticized Google and said fake links still appear above real links in search. Muur also urged users to “double-check links through official X accounts or DeFiLlama” before connecting wallets.
The reports cited did not include a new response from Google. However, DeFi users face added risk when sponsored links copy known crypto platforms. A single wrong click can lead to wallet approvals that send funds to attackers.
SEAL Reports Rise in Search Ad Phishing
DeFiLlama noted that fake Google ads are a common source of phishing attacks in crypto. The warning matched claims from Security Alliance, known as SEAL, in its April report. SEAL said phishing through Google searches rose sharply in March.
According to SEAL, attackers used paid ad accounts and compromised legitimate ad accounts. They created ads that looked safe, so automated checks did not stop them. SEAL said some ads used normal-looking URLs and loaded malicious pages through hidden iframes.
SEAL reported that it blocked more than 356 malicious ad links tied to this activity. The group said attackers kept a steady weekly flow of Google ads for over a year. Reported losses between March 13 and March 30 reached $1.27 million.
The method makes phishing harder for users to spot during normal searches. A sponsored result may appear before the real project site, even on common brand searches. Users can reduce risk by entering official URLs directly and checking trusted project profiles.
Wider Scam Pattern Spreads Across Platforms
The Uniswap case follows other ad-based scams aimed at crypto and tech users. Earlier this month, a malicious ad campaign targeted Mac users through Google ads. The campaign also used shared chats with the AI chatbot Claude, according to the cited reports.
Malwarebytes also reported that Facebook remains a large hub for fake ads and scams. These campaigns often copy known brands, so users may trust them at first glance. Attackers then move victims to fake pages, wallet approvals, or download links.
Australia’s ASIC also warned about crypto scams aimed at young investors on social platforms and WhatsApp. It said scammers use fake trading apps, false profit screenshots, and group chats with fake experts. Victims may later face fake withdrawal fees, while stolen funds are hard to recover.
Crypto users should verify every website before connecting a wallet or signing a transaction. They should avoid sponsored links when handling funds and use bookmarks for trusted sites. Security groups also advise users to check links through official accounts and known crypto data platforms.





