Malicious Ads in Search Results
The first result for a wallet's name has repeatedly been a paid advertisement leading to a phishing page. The defence is one habit.
Priya Raman · 2 min read
Searching for a wallet or exchange by name and clicking the first result has repeatedly led people to phishing pages, because the first result was a paid advertisement bought by an attacker.
How it works
The advertisement is bought against the brand name of a legitimate service. Advertising platforms have policies against this and enforcement is imperfect and slow.
The display URL shows the legitimate domain. Advertising systems permit a display URL distinct from the destination, and attackers exploit the gap. Some campaigns use lookalike domains that survive a glance.
The landing page is a faithful copy. Frequently a complete clone of the real site, including working navigation.
The action is the phishing. Either credential harvesting for an exchange, or a wallet connection request leading to a drain, or a page asking for a recovery phrase to restore a wallet.
Why it catches careful people
The user initiated the search. Nobody sent them a link. The mental model of phishing is that it arrives in a message, and this does not.
The advertisement also appears above the legitimate result, which many users read as ranking rather than as paid placement.
The habit that prevents it
Type the address, or use a bookmark you created yourself.
That is the entire defence. It costs a few seconds and it eliminates the category.
For services you use regularly, bookmark them the first time from a source you have verified, and navigate from the bookmark thereafter.
The additional protections
Scroll past advertisements. The organic result is normally correct. Advertisements are labelled and the label is easy to miss.
Check the domain character by character before entering anything or connecting a wallet. Lookalike domains substitute similar-looking characters and survive a casual glance.
Never restore a wallet from a page you arrived at by search. There is no legitimate situation where a website needs a recovery phrase.
Use a password manager with domain matching. It will not auto-fill on a lookalike domain, which is a reliable signal that something is wrong.
That last one is underrated. The password manager declining to fill is often the only indication a user receives.
Reporting
Advertising platforms have reporting mechanisms for this and they are worth using, because these campaigns run until reported.
The general pattern
This is the same lesson as every other item in this category. The attacker does not need to defeat your judgement about whether a site is legitimate. They need to control which site you arrive at.
Controlling that yourself, by typing the address or using your own bookmark, removes their ability to place themselves in the path. The same applies to exchange logins: navigate to a licensed exchange with a published address or any venue by typing it, never through a search result, and the most common credential-theft route is closed.
Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.