May 31, 2023

Check Point Research observed hundreds of thousands of dollars worth of crypto stolen from wallets by scammers. To lure their victims, scammers placed Google Ads at the top of Google Search that imitated popular wallets and platforms, such as Phantom App, MetaMask and Pancake Swap.

Advertisement contained a malicious link that, once clicked, directed a victim into a phishing website that copied the brand and messaging of the original wallet website. Scammers tricked their victims into giving up their wallet passwords, setting the stage for wallet theft.


A new trend emerged where, multiple scamming groups are now bidding for wallet-related keywords on Google Ads, using Google Search as an attack vector to target victims’ crypto wallets.

  1. Scammer places a Google Ad to appear first on a search query related to a crypto wallet
  2. Victim clicks on malicious link in Google Ad
  3. Victim is navigated to a phishing website that looks identical to the original wallet website
  4. The fake website attempts to steal your passphrase, if you already have a wallet; or will provide you with a new passphrase for your newly created wallet
  5. Scammer gains access to your wallet and can proceed to steal cryptocurrencies

For the domain “”, CPR encountered phishing variants like or, or even different extensions like “.pw” and more.

In total, 11 compromised wallet accounts found, each of them containing between $1K to $10K. CPR went onto learn that the scammers withdrew some of the funds already before CPR’s discovery. By cross-referencing Reddit forums where victims voiced their theft, CPR estimates that over $500k was stolen over the past weekend.


Caution Required

  1. Examine the browser URL. 
  2. Look for the extension icon.
  3. Never give out your passphrase. 
  4. Skip the ads.
  5. Take a look at the URL. 

