HomeSecurityGoogle ads direct users to fake crypto wallets

Google ads direct users to fake crypto wallets

The world of cryptocurrency is full of dangers, with scammers waiting around the corner for newbies. A recent report from security firm Check Point Research highlights one powerful form of attack: the use of Google Ads to direct users to fake crypto wallets. In its report, CPR said it has seen about half a million dollars stolen through these methods in recent days.

See also: Hacker PlugWalkJoe accused of stealing $784,000 in crypto

Google ads

Here’s how the scam works. The attacker buys Google Ads in response to searches for popular crypto wallets (this is software used to store cryptocurrencies, NFTs, and the like). CPR says it has seen scams targeting Phantom and MetaMask wallets, which are the most popular wallets for the Solana and Ethereum ecosystems.

See also: BlackShadow: Hackers breach Israeli company Cyberserve

When an unsuspecting user searches Google for the word “phantom,” the Google ad result (which appears above the real search results) directs them to a phishing website that looks like the real thing. Then, one of two things happens: either the user enters their credentials, which they have, or, even more bizarrely, if they try to create a new wallet, they are told to use a recovery password that actually logs them into a wallet controlled by the attacker, not their own. “This means that if they transfer money, the attacker will immediately take it,” says CPR.

Google ads direct users to fake crypto wallets
crypto wallets

As with phishing scams in general, attackers rely on making fake login pages look as close to the real thing as possible. CPR notes that they have seen attackers use fake URLs to trick users, directing them to phanton.app or phantonn.app, for example, instead of the correct phantom.app. The team has also seen similar phishing scams used to direct users to fake cryptocurrency exchanges, including PancakeSwap and UniSwap.

See also: The Russian Nobelium hackers who hacked SolarWinds strike again!

CPR researchers say they began noticing these scams after seeing crypto users complaining about their losses on Reddit and other forums. They estimate that “at least half a million dollars” have been stolen in recent days.

The team offers a few tips for users hoping to avoid these traps, including never clicking on Google Ads results, but instead looking at search results and always checking the URL of the website they are visiting.

Source of information: theverge.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS