logo

Fake Google Ads Used To Steal Seed Phrases and Drain Crypto Wallets

ID: ce0d0e39-6603-54eb-8e0f-7f12f5245cc2

STIX ID: report--ce0d0e39-6603-54eb-8e0f-7f12f5245cc2

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Varshini

...
...

SEAL warns of a sustained and escalating campaign in which attackers weaponize Google Ads to serve high-reputation Google-owned pages that host cloned frontends and obfuscated scripts to phish cryptocurrency users. The campaign uses cloaking, TDS filtering, Cloudflare Workers and Arweave-hosted entry pages to evade detection, and embeds a man-in-the-middle proxy (via monkey-patched fetch/XHR) to intercept Ethereum RPC calls, enabling real-time wallet monitoring and automated draining via drainer-as-a-service, hardware-wallet seed-phrase stealers, and malicious Chrome extensions; SEAL blocked 356 malicious ad URLs in a three-week window and Google has suspended identified advertiser accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.