Loading article…

Scam using sponsored Google ads mimicking Uniswap drained $400K+ from users; see how the ads worked, on‑chain details and what to watch next.
At least $400,000 vanished after crypto users connected wallets to counterfeit Uniswap sites that appeared as the top Google‑sponsored result for the “Uniswap” keyword — a phishing tactic that highlights the growing risk of ad‑based scams in DeFi [1].
| At a glance | |
|---|---|
| Amount stolen | $400,000+ |
| Method | Sponsored Google ads directing to fake Uniswap pages |
| Wallets affected | Two addresses holding 146 ETH each (≈ $306,000) |
| Catalyst | Scam ads bought by attackers to outrank the official site |
Scammers purchased Google‑Ads slots for the keyword “Uniswap” and posted URLs that closely resemble the real domain, some hosted on Google Sites subdomains. The ads appear above organic results, so users often assume legitimacy [3]. When a user clicks the ad, the clone site mirrors Uniswap’s interface, prompting a wallet connection. Approving a single transaction gives the attacker permission to drain the wallet, an irreversible blockchain operation [1][3]. One trader, known as “ika_xbt,” reported that after approving one transaction his wallet was emptied instantly [1].
On‑chain analyst b‑block flagged the theft on X, identifying two addresses that each held 146 ETH (valued at about $306,000 at the time) before the drain [2][3]. The total loss exceeds $400,000, matching the figure reported by multiple outlets [1][2][3]. The incident adds to a wider trend: crypto‑related scams and exploits caused over $370 million in losses in January 2026 alone [1]. Security Alliance has noted a sharp rise in phishing campaigns linked to Google Search since March 2026, with attackers hijacking ad accounts or buying fresh placements to impersonate major protocols [1].
Uniswap founder Hayden Adams publicly criticized Google for allowing such ads to proliferate, calling for an end to the ad economy that enables these scams [3]. The Web3 marketing agency Green Dots, whose founder Stacy Muur highlighted the issue, urges users to bookmark official URLs and double‑check links before connecting wallets [1][2]. DeFiLlama has launched a Chrome extension, LlamaSearch, to help users verify legitimate crypto domains [3].
The $400K+ loss underscores how easily phishing attacks can bypass even hardware‑wallet safeguards when users are lured by trusted‑looking ads. As scammers continue to exploit ad platforms, the crypto community’s ability to flag and block malicious URLs will be a key factor in limiting future drain events.
Coverage is mostly measured — 6 of 8 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 3 outlets · Jun 16, 2026 · How we report
You can recover your funds by using your 12 or 24-word seed phrase to regenerate your private keys on a new compatible device.
While they protect against online hacking, they can still be lost or damaged, and there is a rare risk of hardware or software vulnerabilities if the device is tampered with before reaching the consumer.
Hot wallets are connected to the internet and are more convenient for frequent, small transactions, whereas hardware wallets operate offline and are intended for secure, long-term storage.