Google Ads are being used by scammers to create fake listings and target crypto wallets, as part of a worrying new vector for cybercrime.
A new study from cybersecurity specialists Check Point Research (CPR) estimated that over $500,000 worth of cryptocurrencies were stolen in a matter of days.
According to CPR, scammers are creating adverts that mimic popular wallet brands, like Phantom, Pancake Swap, and MetaMask. The fraudulent ads then link to phishing websites designed to resemble the real site.
By placing these ads at the top of Google Search, they aim to trick crypto users into clicking them and sharing their wallet passphrases and private keys when they attempt to log in. Once they do, the scammers have access to the victims’ credentials and can log into their real wallet.
The researchers found 11 compromised accounts, each of which contained between $1,000 and $10,000. Scammers had already been able to withdraw some of the money before CPR discovered the fraud.
The $500,000 estimate was made by cross-referencing the thefts with Reddit posts where people mentioned the fraud.
“I believe we’re at the advent of a new cybercrime trend, where scammers will use Google Search as a primary attack vector to reach crypto wallets, instead of traditionally phishing through email,” said Check Point Head of Products Vulnerabilities Research Oded Vanunu.
“In our observation, each advertisement had careful messaging and keyword selection, in order to stand out in search results. The phishing websites where victims were directed to reflected meticulous copying and imitation of wallet brand messaging.
“And what’s most alarming is that multiple scammer groups are bidding for keywords on Google Ads, which is likely a signal of the success of these new phishing campaigns that are geared to heist crypto wallets.”
He added: “Unfortunately, I expect this to become a fast-growing trend in cybercrime. I strongly urge the crypto community to double check the URLs they click on and avoid clicking on Google Ads related to crypto wallets at this time.”
Recommended
- COP26 | The role of digital in building sustainability
- Scots entrepreneurs bag £200k at sustainability award at COP26
- Planet Pollinate game set to “change the way we learn” with VR
CPR advised cryptocurrency holders that they need to stay on high alert against scams.
One tell-tale sign is that the domain name is slightly different. For example, popular cryptocurrency service Phantom’s real website is “phantom.app”. CPR said it found phishing variants with misspelled names, such as “phanton.app” or “phantonn.app”. Some used different extensions like “.pw”.
As such, examining name and extension icon are key pieces of advice CPR provided to stay protected online.
In addition, the cybersecurity experts advised avoiding ads when searching for websites, and never give out a passphrase – websites should never ask for that, except when installing new wallets.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
We will keep you up to date on the pivotal issues impacting the sector and let you know about key upcoming events to ensure that you don’t miss out on what’s going on across the Scottish tech community.
Click here to subscribe.





