Fake Google Ads Used to Steal $400,000 via Uniswap Clones
Fake Google search ads led users to cloned Uniswap pages, where wallet connections and transaction approvals let attackers move at least $400,000 from victims’ wallets.
Attackers bought sponsored search placements that appeared when users searched for “Uniswap” and redirected victims to near-identical copies of the Uniswap web app. At least $400,000 was taken after users connected wallets and approved transactions that granted attackers permission to transfer tokens out of those wallets.
The campaign used paid ads, lookalike domains and cloned interfaces to create a convincing experience. Victims granted token approvals and signed transactions that allowed funds to be moved without any malware, stolen seed phrases or direct access to private keys. In several cases, attackers registered domains with small spelling changes, reused expired domains with search authority, or manipulated organic rankings to surface phishing pages in search results.
Search advertising reaches users precisely when they are ready to act, which made the listings effective. Many users rely on search rather than typing URLs, and top results or sponsored listings can appear authoritative. Experienced DeFi users who move quickly between sites were among those targeted, because rapid approval of requests can be enough to authorize a malicious transfer.
Hardware wallets protected private keys but did not prevent the approvals. Those devices sign the transaction data presented to them and cannot judge whether the signed transaction benefits the user. When a wallet owner approves a request from a cloned interface, the hardware device will sign and enable the transfer as instructed.
Similar impersonation techniques have appeared across platforms, with scam ads, fake livestreams and bogus support accounts mimicking legitimate projects. Attackers use typosquatting and lookalike characters from other alphabets to make malicious URLs hard to spot. When fraudulent ads are removed, campaigns are often relaunched using new accounts or slightly altered domains.
Security professionals recommend several precautions: bookmark official project websites and use bookmarks instead of searching for destinations; avoid sponsored links for wallet downloads and exchange access; check URLs carefully for spelling errors and unusual characters before connecting a wallet; review transaction requests and permission scopes slowly before approving; use wallet tools that flag unusual approvals or simulate transactions; and revoke token approvals that are no longer needed.
Blockchain transactions are typically final, and attackers can rebuild ad campaigns quickly. Users who encounter unexpected or unfamiliar approval requests are advised to pause and verify the site and transaction details before signing.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








