logo

Malicious Google Ads Target Crypto Users With Wallet Drainers and Seed Phrase Theft

ID: 37ee1900-c345-5395-aac1-fd3858b32895

STIX ID: report--37ee1900-c345-5395-aac1-fd3858b32895

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Tushar Subhra Dutta

...
...

SecurityAlliance (SEAL) documents a widespread 2026 campaign in which criminals weaponize Google Ads to impersonate major crypto services (e.g., Uniswap, Morpho, Ledger) and deliver wallet-draining JavaScript, seed-phrase stealers, and fake browser extensions via trusted Google domains, hidden iframes, fingerprinting, and man-in-the-middle proxies; SEAL blocked 356 malicious ad URLs and attributes at least $1.27M in confirmed thefts during mid‑March 2026 while urging users to access crypto sites only via bookmarked trusted URLs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.