{"id":12334,"date":"2026-04-23T10:03:48","date_gmt":"2026-04-23T10:03:48","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/23\/malicious-google-ads-target-crypto-users-with-wallet-drainers-and-seed-phrase-theft\/"},"modified":"2026-04-23T10:03:48","modified_gmt":"2026-04-23T10:03:48","slug":"malicious-google-ads-target-crypto-users-with-wallet-drainers-and-seed-phrase-theft","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/23\/malicious-google-ads-target-crypto-users-with-wallet-drainers-and-seed-phrase-theft\/","title":{"rendered":"Malicious Google Ads Target Crypto Users With Wallet Drainers and Seed Phrase Theft"},"content":{"rendered":"<p>    Malicious Google Ads Target Crypto Users With Wallet Drainers and Seed Phrase Theft<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybercriminals are now using Google\u2019s own advertising platform to steal cryptocurrency from unsuspecting users. <\/p>\n<p>They place <a href=\"https:\/\/cybersecuritynews.com\/beware-of-malicious-slack-ads\/\" id=\"75850\" target=\"_blank\" rel=\"noreferrer noopener\">fake ads<\/a> that look exactly like real links to popular crypto applications, and when users click on them, they land on websites designed to drain their wallets or trick them into giving away their secret recovery phrases.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/2ddb9a9b-a781-49e3-b6f8-ab00fcdc8aa0\/Malicious-Google-Ads-Target-Crypto-Users-With-Wallet-Drainers-and-Seed-Phrase-Theft.pdf?AWSAccessKeyId=ASIA2F3EMEYEQATX2UJI&amp;Signature=5Yod58o9wbAsUfmLuRvP9EbbgGA%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIB%2FoG%2FVpXEZzzVL0DwqmkMUBQOiQPuVk11s4yifSwFibAiB9wXTOll98F3ogeWJtrRiVfL5LqwDvdKW%2BtoMBwsPPfCrzBAhVEAEaDDY5OTc1MzMwOTcwNSIMzJQnPzV2XVC78T%2BiKtAEFQfqOKAAbAzNNff0Y%2FyMbH6gt%2BPpYlclImZ%2FZtplmnC01eAu%2B4dIVdAwZRSvXsCeEtcUzapWHwgtbRvxaspou6XeXFstn9C73I09Ri8dMulYU0Y%2BSzpdFAQC%2B7Xkxd03BGL7qx0RKLTLHXV06yA1QHIlt4mIUSe8dsSAXnHOSrIgxVl3urhOMrVWmva2LlsuJlf1qArc6kIdD3RULrv4C67fAY2J9RulCdFIiyQSKDlfBKXqYgRGn81EN2i0qrS%2FOh0HCUqhZgc%2FwLlY6HvEJA737dNaxlo6qmpVXzUT2ey1mjSticPEc0Tz4bDHluNvLQmai26rFh9ulsNBnPrtf7KdOWBIwEHREceE9qkmeXYYdd6ndkQP0DDiYdncwJ%2FJoVXcBXlTARngTvYYAdG8iokAdkz5dyxaaZNbmOgd%2FeGRMUSo2yOaJdmGoFjAdMQA3FLGp%2FZrTaq%2BbEDXSa2B7sZyhDvXWFJi%2Bg%2F2kntNi9tMV39EyGCjfPrNzLdqEbZ6PJQo56uuRyZa3gdcSXzebV84NILBX5L0RBnPTvMBbiELygqZQUho%2FaHZJylnyQW0gkpf0HMOeCm4%2FTNc1TBrK5Nw5%2F09zxxitcAx9XVM5ddr22T9hU6Buzlo2IliO7G4pdgS2b4jXboYMzCjPxjMnV6KSj10QIHG3DzgOqzMAyhpfznEpIY7M61mZoxsLta57HrvxQi06%2BAVrClwos44tfwdPuM2d9ZsEPojCLkT11MY2r0CD0ENK4TWipDfqyaeQ8iVKMsvintPMVyREuoR7TCkyKTPBjqZAQegaoQs0B31XSTl8RC5Ls%2BRZurRswVWGM8A4MYEzHlvZYLR%2FgXhk0T%2BI1oj%2FR4%2FCiuLltczvdGxIY%2BuOqabXRKlOpSWcqi7IbjTP9EJYFpbn5B0d3X8pYypcyDKgL6PLVk4nsbi6yxh857cM0MOjp0IWUNnl1GgFVXA2dbS78bAKmtf2R9hJPHldbfeHwu5Z02MXwI2rIU2Ng%3D%3D&amp;Expires=1776889622\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>This type of attack is not new, but it has grown sharply in 2026. In March alone, activity reached a significant peak, with threat actors running fake ads every week for more than a year. <\/p>\n<p>These campaigns targeted some of the most widely used platforms, including Uniswap, PancakeSwap, Morpho Finance, Hyperliquid, CoW Swap, and hardware wallet brand Ledger. <\/p>\n<p>The scale and consistency of the operation point to a well-organized criminal effort that shows no sign of slowing down.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/2ddb9a9b-a781-49e3-b6f8-ab00fcdc8aa0\/Malicious-Google-Ads-Target-Crypto-Users-With-Wallet-Drainers-and-Seed-Phrase-Theft.pdf?AWSAccessKeyId=ASIA2F3EMEYEQATX2UJI&amp;Signature=5Yod58o9wbAsUfmLuRvP9EbbgGA%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIB%2FoG%2FVpXEZzzVL0DwqmkMUBQOiQPuVk11s4yifSwFibAiB9wXTOll98F3ogeWJtrRiVfL5LqwDvdKW%2BtoMBwsPPfCrzBAhVEAEaDDY5OTc1MzMwOTcwNSIMzJQnPzV2XVC78T%2BiKtAEFQfqOKAAbAzNNff0Y%2FyMbH6gt%2BPpYlclImZ%2FZtplmnC01eAu%2B4dIVdAwZRSvXsCeEtcUzapWHwgtbRvxaspou6XeXFstn9C73I09Ri8dMulYU0Y%2BSzpdFAQC%2B7Xkxd03BGL7qx0RKLTLHXV06yA1QHIlt4mIUSe8dsSAXnHOSrIgxVl3urhOMrVWmva2LlsuJlf1qArc6kIdD3RULrv4C67fAY2J9RulCdFIiyQSKDlfBKXqYgRGn81EN2i0qrS%2FOh0HCUqhZgc%2FwLlY6HvEJA737dNaxlo6qmpVXzUT2ey1mjSticPEc0Tz4bDHluNvLQmai26rFh9ulsNBnPrtf7KdOWBIwEHREceE9qkmeXYYdd6ndkQP0DDiYdncwJ%2FJoVXcBXlTARngTvYYAdG8iokAdkz5dyxaaZNbmOgd%2FeGRMUSo2yOaJdmGoFjAdMQA3FLGp%2FZrTaq%2BbEDXSa2B7sZyhDvXWFJi%2Bg%2F2kntNi9tMV39EyGCjfPrNzLdqEbZ6PJQo56uuRyZa3gdcSXzebV84NILBX5L0RBnPTvMBbiELygqZQUho%2FaHZJylnyQW0gkpf0HMOeCm4%2FTNc1TBrK5Nw5%2F09zxxitcAx9XVM5ddr22T9hU6Buzlo2IliO7G4pdgS2b4jXboYMzCjPxjMnV6KSj10QIHG3DzgOqzMAyhpfznEpIY7M61mZoxsLta57HrvxQi06%2BAVrClwos44tfwdPuM2d9ZsEPojCLkT11MY2r0CD0ENK4TWipDfqyaeQ8iVKMsvintPMVyREuoR7TCkyKTPBjqZAQegaoQs0B31XSTl8RC5Ls%2BRZurRswVWGM8A4MYEzHlvZYLR%2FgXhk0T%2BI1oj%2FR4%2FCiuLltczvdGxIY%2BuOqabXRKlOpSWcqi7IbjTP9EJYFpbn5B0d3X8pYypcyDKgL6PLVk4nsbi6yxh857cM0MOjp0IWUNnl1GgFVXA2dbS78bAKmtf2R9hJPHldbfeHwu5Z02MXwI2rIU2Ng%3D%3D&amp;Expires=1776889622\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p><a href=\"https:\/\/radar.securityalliance.org\/malicious-google-ads-targeting-crypto\/\" id=\"https:\/\/radar.securityalliance.org\/malicious-google-ads-targeting-crypto\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">SecurityAlliance (SEAL) analysts identified and actively tracked multiple threat actors<\/a> behind these campaigns. <\/p>\n<p>Researchers noted that attackers are using three types of malicious payloads: cryptocurrency wallet drainers, seed phrase stealers, and fake browser extensions. <\/p>\n<p>Wallet drainers use in-browser JavaScript to push victims into approving a harmful transaction, while seed phrase stealers present a cloned website where users are prompted to type their wallet recovery phrase directly. <\/p>\n<p>Fake browser extensions distributed through Chrome Web Store links round out the attack toolkit. In just a few weeks, SEAL blocked over 356 malicious advertisement URLs, a number that reflects only a fraction of the true scale.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/2ddb9a9b-a781-49e3-b6f8-ab00fcdc8aa0\/Malicious-Google-Ads-Target-Crypto-Users-With-Wallet-Drainers-and-Seed-Phrase-Theft.pdf?AWSAccessKeyId=ASIA2F3EMEYEQATX2UJI&amp;Signature=5Yod58o9wbAsUfmLuRvP9EbbgGA%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIB%2FoG%2FVpXEZzzVL0DwqmkMUBQOiQPuVk11s4yifSwFibAiB9wXTOll98F3ogeWJtrRiVfL5LqwDvdKW%2BtoMBwsPPfCrzBAhVEAEaDDY5OTc1MzMwOTcwNSIMzJQnPzV2XVC78T%2BiKtAEFQfqOKAAbAzNNff0Y%2FyMbH6gt%2BPpYlclImZ%2FZtplmnC01eAu%2B4dIVdAwZRSvXsCeEtcUzapWHwgtbRvxaspou6XeXFstn9C73I09Ri8dMulYU0Y%2BSzpdFAQC%2B7Xkxd03BGL7qx0RKLTLHXV06yA1QHIlt4mIUSe8dsSAXnHOSrIgxVl3urhOMrVWmva2LlsuJlf1qArc6kIdD3RULrv4C67fAY2J9RulCdFIiyQSKDlfBKXqYgRGn81EN2i0qrS%2FOh0HCUqhZgc%2FwLlY6HvEJA737dNaxlo6qmpVXzUT2ey1mjSticPEc0Tz4bDHluNvLQmai26rFh9ulsNBnPrtf7KdOWBIwEHREceE9qkmeXYYdd6ndkQP0DDiYdncwJ%2FJoVXcBXlTARngTvYYAdG8iokAdkz5dyxaaZNbmOgd%2FeGRMUSo2yOaJdmGoFjAdMQA3FLGp%2FZrTaq%2BbEDXSa2B7sZyhDvXWFJi%2Bg%2F2kntNi9tMV39EyGCjfPrNzLdqEbZ6PJQo56uuRyZa3gdcSXzebV84NILBX5L0RBnPTvMBbiELygqZQUho%2FaHZJylnyQW0gkpf0HMOeCm4%2FTNc1TBrK5Nw5%2F09zxxitcAx9XVM5ddr22T9hU6Buzlo2IliO7G4pdgS2b4jXboYMzCjPxjMnV6KSj10QIHG3DzgOqzMAyhpfznEpIY7M61mZoxsLta57HrvxQi06%2BAVrClwos44tfwdPuM2d9ZsEPojCLkT11MY2r0CD0ENK4TWipDfqyaeQ8iVKMsvintPMVyREuoR7TCkyKTPBjqZAQegaoQs0B31XSTl8RC5Ls%2BRZurRswVWGM8A4MYEzHlvZYLR%2FgXhk0T%2BI1oj%2FR4%2FCiuLltczvdGxIY%2BuOqabXRKlOpSWcqi7IbjTP9EJYFpbn5B0d3X8pYypcyDKgL6PLVk4nsbi6yxh857cM0MOjp0IWUNnl1GgFVXA2dbS78bAKmtf2R9hJPHldbfeHwu5Z02MXwI2rIU2Ng%3D%3D&amp;Expires=1776889622\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The financial damage confirmed so far is severe. Between March 13 and March 30, 2026, at least $1,274,259 was stolen from victims, with $810,929 directly linked to specific attacks. <\/p>\n<p>One single theft in early March 2026 alone reached $385,000. SEAL notes that the actual total is likely far greater, since reliable attribution is only possible when victims come forward with full details. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiIxLv0PDgN6qnEfBxWz0Bk5gq9QT83mrHE_nwAaXGaoTDM1yeuRnBLnFJpPzMj2Ts8OV4uXfHl5q3sZ8f4ffAsHZJPBosxnwz-oXFkrJEtfhsQfbj2AzLc9RYvIbvYszb_0F8fuxzWuCQF4i9fx0-z0idgrexiI1_k5K3e7XkaXKcJDQdv2MjdNdL_s-c\/s16000\/Brand%2520Impersonation%2520%28Source%2520-%2520SecurityAlliance%29.webp?ssl=1\" alt=\"Brand Impersonation (Source - SecurityAlliance)\"><figcaption class=\"wp-element-caption\">Brand Impersonation (Source \u2013 SecurityAlliance)<\/figcaption><\/figure>\n<\/div>\n<p>Uniswap was the most impersonated brand at 41% of all detected malicious sites, followed by Morpho Finance at 31%.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/2ddb9a9b-a781-49e3-b6f8-ab00fcdc8aa0\/Malicious-Google-Ads-Target-Crypto-Users-With-Wallet-Drainers-and-Seed-Phrase-Theft.pdf?AWSAccessKeyId=ASIA2F3EMEYEQATX2UJI&amp;Signature=5Yod58o9wbAsUfmLuRvP9EbbgGA%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIB%2FoG%2FVpXEZzzVL0DwqmkMUBQOiQPuVk11s4yifSwFibAiB9wXTOll98F3ogeWJtrRiVfL5LqwDvdKW%2BtoMBwsPPfCrzBAhVEAEaDDY5OTc1MzMwOTcwNSIMzJQnPzV2XVC78T%2BiKtAEFQfqOKAAbAzNNff0Y%2FyMbH6gt%2BPpYlclImZ%2FZtplmnC01eAu%2B4dIVdAwZRSvXsCeEtcUzapWHwgtbRvxaspou6XeXFstn9C73I09Ri8dMulYU0Y%2BSzpdFAQC%2B7Xkxd03BGL7qx0RKLTLHXV06yA1QHIlt4mIUSe8dsSAXnHOSrIgxVl3urhOMrVWmva2LlsuJlf1qArc6kIdD3RULrv4C67fAY2J9RulCdFIiyQSKDlfBKXqYgRGn81EN2i0qrS%2FOh0HCUqhZgc%2FwLlY6HvEJA737dNaxlo6qmpVXzUT2ey1mjSticPEc0Tz4bDHluNvLQmai26rFh9ulsNBnPrtf7KdOWBIwEHREceE9qkmeXYYdd6ndkQP0DDiYdncwJ%2FJoVXcBXlTARngTvYYAdG8iokAdkz5dyxaaZNbmOgd%2FeGRMUSo2yOaJdmGoFjAdMQA3FLGp%2FZrTaq%2BbEDXSa2B7sZyhDvXWFJi%2Bg%2F2kntNi9tMV39EyGCjfPrNzLdqEbZ6PJQo56uuRyZa3gdcSXzebV84NILBX5L0RBnPTvMBbiELygqZQUho%2FaHZJylnyQW0gkpf0HMOeCm4%2FTNc1TBrK5Nw5%2F09zxxitcAx9XVM5ddr22T9hU6Buzlo2IliO7G4pdgS2b4jXboYMzCjPxjMnV6KSj10QIHG3DzgOqzMAyhpfznEpIY7M61mZoxsLta57HrvxQi06%2BAVrClwos44tfwdPuM2d9ZsEPojCLkT11MY2r0CD0ENK4TWipDfqyaeQ8iVKMsvintPMVyREuoR7TCkyKTPBjqZAQegaoQs0B31XSTl8RC5Ls%2BRZurRswVWGM8A4MYEzHlvZYLR%2FgXhk0T%2BI1oj%2FR4%2FCiuLltczvdGxIY%2BuOqabXRKlOpSWcqi7IbjTP9EJYFpbn5B0d3X8pYypcyDKgL6PLVk4nsbi6yxh857cM0MOjp0IWUNnl1GgFVXA2dbS78bAKmtf2R9hJPHldbfeHwu5Z02MXwI2rIU2Ng%3D%3D&amp;Expires=1776889622\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"how-the-attack-infrastructure-works\"><strong>How the Attack Infrastructure Works<\/strong><\/h2>\n<p>One of the most revealing aspects of this campaign is the delivery mechanism behind the fake ads. Instead of pointing directly to a harmful page, attackers use a layered architecture that makes the threat invisible to Google\u2019s automated detection systems. <\/p>\n<p>The ad links to a page hosted on trusted Google-owned domains like sites.google.com or docs.google.com, which allows it to pass Google\u2019s review process since the initial URL appears completely safe.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/2ddb9a9b-a781-49e3-b6f8-ab00fcdc8aa0\/Malicious-Google-Ads-Target-Crypto-Users-With-Wallet-Drainers-and-Seed-Phrase-Theft.pdf?AWSAccessKeyId=ASIA2F3EMEYEQATX2UJI&amp;Signature=5Yod58o9wbAsUfmLuRvP9EbbgGA%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIB%2FoG%2FVpXEZzzVL0DwqmkMUBQOiQPuVk11s4yifSwFibAiB9wXTOll98F3ogeWJtrRiVfL5LqwDvdKW%2BtoMBwsPPfCrzBAhVEAEaDDY5OTc1MzMwOTcwNSIMzJQnPzV2XVC78T%2BiKtAEFQfqOKAAbAzNNff0Y%2FyMbH6gt%2BPpYlclImZ%2FZtplmnC01eAu%2B4dIVdAwZRSvXsCeEtcUzapWHwgtbRvxaspou6XeXFstn9C73I09Ri8dMulYU0Y%2BSzpdFAQC%2B7Xkxd03BGL7qx0RKLTLHXV06yA1QHIlt4mIUSe8dsSAXnHOSrIgxVl3urhOMrVWmva2LlsuJlf1qArc6kIdD3RULrv4C67fAY2J9RulCdFIiyQSKDlfBKXqYgRGn81EN2i0qrS%2FOh0HCUqhZgc%2FwLlY6HvEJA737dNaxlo6qmpVXzUT2ey1mjSticPEc0Tz4bDHluNvLQmai26rFh9ulsNBnPrtf7KdOWBIwEHREceE9qkmeXYYdd6ndkQP0DDiYdncwJ%2FJoVXcBXlTARngTvYYAdG8iokAdkz5dyxaaZNbmOgd%2FeGRMUSo2yOaJdmGoFjAdMQA3FLGp%2FZrTaq%2BbEDXSa2B7sZyhDvXWFJi%2Bg%2F2kntNi9tMV39EyGCjfPrNzLdqEbZ6PJQo56uuRyZa3gdcSXzebV84NILBX5L0RBnPTvMBbiELygqZQUho%2FaHZJylnyQW0gkpf0HMOeCm4%2FTNc1TBrK5Nw5%2F09zxxitcAx9XVM5ddr22T9hU6Buzlo2IliO7G4pdgS2b4jXboYMzCjPxjMnV6KSj10QIHG3DzgOqzMAyhpfznEpIY7M61mZoxsLta57HrvxQi06%2BAVrClwos44tfwdPuM2d9ZsEPojCLkT11MY2r0CD0ENK4TWipDfqyaeQ8iVKMsvintPMVyREuoR7TCkyKTPBjqZAQegaoQs0B31XSTl8RC5Ls%2BRZurRswVWGM8A4MYEzHlvZYLR%2FgXhk0T%2BI1oj%2FR4%2FCiuLltczvdGxIY%2BuOqabXRKlOpSWcqi7IbjTP9EJYFpbn5B0d3X8pYypcyDKgL6PLVk4nsbi6yxh857cM0MOjp0IWUNnl1GgFVXA2dbS78bAKmtf2R9hJPHldbfeHwu5Z02MXwI2rIU2Ng%3D%3D&amp;Expires=1776889622\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The actual malicious content loads separately through hidden iframes, paired with fingerprinting and cloaking scripts. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjM637XGP1wsQ1HdwWxhBJLzu6zOIu7WNHqytwdaMrjIvzIGnUgyamgcp2RrkcmczH4y4rD9zWl9gxFmrUX4e9nPSFWo6VN1IMycp7B8gkuq5QRhmGOGZNQIgd9a5e2ZUGifk09GoR7r9YxXQxqOvdZJaqd5Ce1wk212d74jsi6570aQn-egRIdt7eihlI\/s16000\/Fake%2520ads%2520%28Source%2520-%2520SecurityAlliance%29.webp?ssl=1\" alt=\"Fake ads (Source - SecurityAlliance)\"><figcaption class=\"wp-element-caption\">Fake ads (Source \u2013 SecurityAlliance)<\/figcaption><\/figure>\n<\/div>\n<p>These scripts check whether a visitor is a security researcher or a real user, and respond differently in each case. Non-targeted visitors get sent to harmless pages like Wikipedia, while actual users are served a fully cloned version of the target application that looks visually identical to the original.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/2ddb9a9b-a781-49e3-b6f8-ab00fcdc8aa0\/Malicious-Google-Ads-Target-Crypto-Users-With-Wallet-Drainers-and-Seed-Phrase-Theft.pdf?AWSAccessKeyId=ASIA2F3EMEYEQATX2UJI&amp;Signature=5Yod58o9wbAsUfmLuRvP9EbbgGA%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIB%2FoG%2FVpXEZzzVL0DwqmkMUBQOiQPuVk11s4yifSwFibAiB9wXTOll98F3ogeWJtrRiVfL5LqwDvdKW%2BtoMBwsPPfCrzBAhVEAEaDDY5OTc1MzMwOTcwNSIMzJQnPzV2XVC78T%2BiKtAEFQfqOKAAbAzNNff0Y%2FyMbH6gt%2BPpYlclImZ%2FZtplmnC01eAu%2B4dIVdAwZRSvXsCeEtcUzapWHwgtbRvxaspou6XeXFstn9C73I09Ri8dMulYU0Y%2BSzpdFAQC%2B7Xkxd03BGL7qx0RKLTLHXV06yA1QHIlt4mIUSe8dsSAXnHOSrIgxVl3urhOMrVWmva2LlsuJlf1qArc6kIdD3RULrv4C67fAY2J9RulCdFIiyQSKDlfBKXqYgRGn81EN2i0qrS%2FOh0HCUqhZgc%2FwLlY6HvEJA737dNaxlo6qmpVXzUT2ey1mjSticPEc0Tz4bDHluNvLQmai26rFh9ulsNBnPrtf7KdOWBIwEHREceE9qkmeXYYdd6ndkQP0DDiYdncwJ%2FJoVXcBXlTARngTvYYAdG8iokAdkz5dyxaaZNbmOgd%2FeGRMUSo2yOaJdmGoFjAdMQA3FLGp%2FZrTaq%2BbEDXSa2B7sZyhDvXWFJi%2Bg%2F2kntNi9tMV39EyGCjfPrNzLdqEbZ6PJQo56uuRyZa3gdcSXzebV84NILBX5L0RBnPTvMBbiELygqZQUho%2FaHZJylnyQW0gkpf0HMOeCm4%2FTNc1TBrK5Nw5%2F09zxxitcAx9XVM5ddr22T9hU6Buzlo2IliO7G4pdgS2b4jXboYMzCjPxjMnV6KSj10QIHG3DzgOqzMAyhpfznEpIY7M61mZoxsLta57HrvxQi06%2BAVrClwos44tfwdPuM2d9ZsEPojCLkT11MY2r0CD0ENK4TWipDfqyaeQ8iVKMsvintPMVyREuoR7TCkyKTPBjqZAQegaoQs0B31XSTl8RC5Ls%2BRZurRswVWGM8A4MYEzHlvZYLR%2FgXhk0T%2BI1oj%2FR4%2FCiuLltczvdGxIY%2BuOqabXRKlOpSWcqi7IbjTP9EJYFpbn5B0d3X8pYypcyDKgL6PLVk4nsbi6yxh857cM0MOjp0IWUNnl1GgFVXA2dbS78bAKmtf2R9hJPHldbfeHwu5Z02MXwI2rIU2Ng%3D%3D&amp;Expires=1776889622\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>A man-in-the-middle proxy layer then intercepts all network traffic generated by the cloned interface, including Ethereum transaction calls, and routes them through the attacker\u2019s backend before they reach any real endpoint. <\/p>\n<p>This gives attackers live visibility into a victim\u2019s wallet balance and activity. When SEAL blocks a malicious URL, the attacker\u2019s system detects it almost immediately and relaunches the campaign with a fresh ad and a new <a href=\"https:\/\/cybersecuritynews.com\/landing-page-security-how-to-manage-compliance-and-improve-performance\/\" id=\"132015\" target=\"_blank\" rel=\"noreferrer noopener\">landing page<\/a>, sometimes within minutes of the takedown.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/2ddb9a9b-a781-49e3-b6f8-ab00fcdc8aa0\/Malicious-Google-Ads-Target-Crypto-Users-With-Wallet-Drainers-and-Seed-Phrase-Theft.pdf?AWSAccessKeyId=ASIA2F3EMEYEQATX2UJI&amp;Signature=5Yod58o9wbAsUfmLuRvP9EbbgGA%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIB%2FoG%2FVpXEZzzVL0DwqmkMUBQOiQPuVk11s4yifSwFibAiB9wXTOll98F3ogeWJtrRiVfL5LqwDvdKW%2BtoMBwsPPfCrzBAhVEAEaDDY5OTc1MzMwOTcwNSIMzJQnPzV2XVC78T%2BiKtAEFQfqOKAAbAzNNff0Y%2FyMbH6gt%2BPpYlclImZ%2FZtplmnC01eAu%2B4dIVdAwZRSvXsCeEtcUzapWHwgtbRvxaspou6XeXFstn9C73I09Ri8dMulYU0Y%2BSzpdFAQC%2B7Xkxd03BGL7qx0RKLTLHXV06yA1QHIlt4mIUSe8dsSAXnHOSrIgxVl3urhOMrVWmva2LlsuJlf1qArc6kIdD3RULrv4C67fAY2J9RulCdFIiyQSKDlfBKXqYgRGn81EN2i0qrS%2FOh0HCUqhZgc%2FwLlY6HvEJA737dNaxlo6qmpVXzUT2ey1mjSticPEc0Tz4bDHluNvLQmai26rFh9ulsNBnPrtf7KdOWBIwEHREceE9qkmeXYYdd6ndkQP0DDiYdncwJ%2FJoVXcBXlTARngTvYYAdG8iokAdkz5dyxaaZNbmOgd%2FeGRMUSo2yOaJdmGoFjAdMQA3FLGp%2FZrTaq%2BbEDXSa2B7sZyhDvXWFJi%2Bg%2F2kntNi9tMV39EyGCjfPrNzLdqEbZ6PJQo56uuRyZa3gdcSXzebV84NILBX5L0RBnPTvMBbiELygqZQUho%2FaHZJylnyQW0gkpf0HMOeCm4%2FTNc1TBrK5Nw5%2F09zxxitcAx9XVM5ddr22T9hU6Buzlo2IliO7G4pdgS2b4jXboYMzCjPxjMnV6KSj10QIHG3DzgOqzMAyhpfznEpIY7M61mZoxsLta57HrvxQi06%2BAVrClwos44tfwdPuM2d9ZsEPojCLkT11MY2r0CD0ENK4TWipDfqyaeQ8iVKMsvintPMVyREuoR7TCkyKTPBjqZAQegaoQs0B31XSTl8RC5Ls%2BRZurRswVWGM8A4MYEzHlvZYLR%2FgXhk0T%2BI1oj%2FR4%2FCiuLltczvdGxIY%2BuOqabXRKlOpSWcqi7IbjTP9EJYFpbn5B0d3X8pYypcyDKgL6PLVk4nsbi6yxh857cM0MOjp0IWUNnl1GgFVXA2dbS78bAKmtf2R9hJPHldbfeHwu5Z02MXwI2rIU2Ng%3D%3D&amp;Expires=1776889622\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>SEAL urges all cryptocurrency users to stop using <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploiting-google-search-ads\/\" id=\"86344\" target=\"_blank\" rel=\"noreferrer noopener\">Google Search<\/a> when navigating to crypto applications. Users should save trusted URLs as bookmarks and access them directly every time. <\/p>\n<p>For link verification, cryptocurrency-specific indexing tools like search.defillama.com can confirm the correct site before connecting a wallet. <\/p>\n<p>Organizations managing digital assets should enforce strict direct-URL access policies and avoid clicking any search result, including those labeled as sponsored. <\/p>\n<p>Google has suspended all advertiser accounts identified in this report, but the campaign continues as new accounts are deployed quickly. Staying alert and relying only on bookmarked links remains the most reliable protection available today.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/malicious-google-ads-target-crypto-users\/\">Malicious Google Ads Target Crypto Users With Wallet Drainers and Seed Phrase Theft<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/malicious-google-ads-target-crypto-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malicious Google Ads Target Crypto Users With Wallet Drainers and Seed Phrase Theft Cybercriminals are now using Google\u2019s own advertising platform to steal cryptocurrency from unsuspecting users. They place fake ads that look exactly like real links to popular crypto applications, and when users click on them, they land on websites designed to drain their [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-12334","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12334"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12334"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12334\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12334"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12334"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12334"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}