Crypto users lose $3 million on phishing sites promoted by Google Ads in 24 hours
In total, more than 63 000 people have fallen victim to scammers since the beginning of the year
26.12.2023 - 15:05
576
2 min
0
What’s new? In 24 hours, scammers stole $3 million from crypto users through phishing sites with malware to withdraw funds from wallets promoted through Google Ads. According to Scam Sniffer, an audit company, victims lost WBTC, aPolUSDT, aUSDC, and USDT coins on December 25. In total, these attackers have stolen more than $60 million in cryptocurrencies in a similar manner since the beginning of the year.
What else is known? Back on December 21, Scam Sniffer identified addresses associated with the theft of funds through fake websites of Zapper, Lido, Stargate, DefiLlama, Orbiter Finance, and Radient projects that are advertised on Google. Auditors have reported the matter to Google Ads security, but have not yet received a response.
Scam Sniffer called phishing a major threat to users and recommended that all signature requests be thoroughly checked before conducting transactions.
According to the analysts’ research, more than 63 000 users were affected by the malware called MS Drainer. The company identified 10 072 fake websites mimicking the official pages of cryptocurrency projects. In September, an unknown Ethereum wallet lost over $24 million in this way, becoming the largest victim of scammers.
The problem with the promotion of phishing sites in Google Ads is not new: earlier this year, user X under the nickname @NFT_GOD accused the corporation of losing all its digital assets as a result of interaction with a malicious resource. And in April, the damage to users from crypto phishing in Google Ads exceeded $4 million.
Useful material?
Incidents
The company is linking the incident to a compromised private key on a service wallet, rather than a smart contract exploit
May 22, 2026
Incidents
Following the incident, the project temporarily halted trading operations and node activity.
May 15, 2026
Incidents
The user spent weeks unsuccessfully trying to guess the password until Claude helped find an old wallet backup file
May 14, 2026
Crypto regulations
Authorities are introducing mandatory registration for companies handling cross-border crypto transactions
May 8, 2026
Incidents
According to Blockaid, the attack may have been carried out by the same hacker behind the 1inch Fusion V1 exploit.
May 7, 2026
Incidents
The attacker gained administrative access and altered contracts to drain user funds
Apr 30, 2026
Telegram
Twitter