Web Analytics
Crypto Potato
2026-05-26 23:45:37

Fake Uniswap Website Drains Crypto Wallets as Scammers Pocket $400K

A fake website impersonating Uniswap is draining funds from multiple crypto wallets. The prominent on-chain analyst, pseudonymously known as “b-block,” warned that the scammers currently control at least $400,000 in stolen assets. Users were urged to rely only on official links and verify protocols through DefiLlama. Uniswap Tops List of Most-Targeted Platforms The latest update comes a month after security group SEAL reported a major rise in malicious Google Ads targeting crypto users. It found that attackers were impersonating popular DeFi platforms, wallets, and trading applications to steal funds. SEAL said it recently blocked over 356 malicious Google ad URLs tied to crypto scams, which targeted platforms such as Uniswap, Morpho Finance, PancakeSwap, Hyperliquid, CoW Swap, and 1inch users According to the report, attackers used hacked or fraudulently obtained Google advertiser accounts and relied on cloaking, fingerprinting, and nested iframe delivery systems to bypass Google’s automated review checks. Many of the fake ads used trusted Google services such as sites.google.com and docs.google.com to appear legitimate in search results. SEAL identified crypto drainer families, including Inferno Drainer and Vanilla Drainer, as the most commonly used malware in the campaigns. The report said these tools trick users into signing malicious wallet transactions or entering recovery seed phrases on cloned websites, allowing attackers to take control of wallet assets. SEAL also added that the advanced infrastructure used in the attacks, including Cloudflare Workers, Arweave-hosted payloads, traffic redirection systems, and proxy layers, can intercept Ethereum RPC requests and monitor user activity in real time. Uniswap was the most impersonated platform, accounting for 41% of tracked malicious sites. Between March 13 and March 30, confirmed and unattributed losses linked to the campaigns exceeded $1.27 million, although the security group said the actual figure was likely significantly higher. Rampant Phishing Campaigns While the recent Uniswap-related scams mainly involved fake websites and malicious Google Ads, a separate phishing campaign earlier this year targeted Ledger users through fraudulent emails. The attack followed a data breach at Ledger’s third-party e-commerce partner, Global-e, which exposed customer contact and order information. The scammers claimed in emails that Ledger and Trezor had merged and urged users to migrate their wallets via fake websites that requested 24-word recovery phrases. The phishing pages closely copied the companies’ official branding and messaging styles. More recently, Ripple CTO David Schwartz warned of a phishing campaign that sent fake security alerts that appeared to come from Robinhood’s official email system. The emails passed authentication checks because attackers exploited Robinhood’s account creation flow, which made the messages appear legitimate. The phishing note claimed a new login from an “iPhone 17 Pro” and prompted users to review suspicious activity through a “Review Activity Now” button, which then directed them toward credential theft. Robinhood later confirmed the issue, but stated that no systems were breached and no funds were affected. The post Fake Uniswap Website Drains Crypto Wallets as Scammers Pocket $400K appeared first on CryptoPotato .

获取加密通讯
阅读免责声明 : 此处提供的所有内容我们的网站,超链接网站,相关应用程序,论坛,博客,社交媒体帐户和其他平台(“网站”)仅供您提供一般信息,从第三方采购。 我们不对与我们的内容有任何形式的保证,包括但不限于准确性和更新性。 我们提供的内容中没有任何内容构成财务建议,法律建议或任何其他形式的建议,以满足您对任何目的的特定依赖。 任何使用或依赖我们的内容完全由您自行承担风险和自由裁量权。 在依赖它们之前,您应该进行自己的研究,审查,分析和验证我们的内容。 交易是一项高风险的活动,可能导致重大损失,因此请在做出任何决定之前咨询您的财务顾问。 我们网站上的任何内容均不构成招揽或要约