Security monitoring account ScamSniffer has warned that Google search results for several major DeFi protocols are currently saturated with malicious sponsored ads impersonating the official sites for Aave, PancakeSwap, and Pendle. According to their alert, users searching these protocol names on Google are being shown phishing links as the top results, where a single mistaken click followed by signing a transaction can allow attackers to drain the victim’s wallet. Binance’s security team amplified the same warning, noting that fake sites for these projects are “topping Google search results,” and urging users to be extremely cautious when accessing DeFi services via search engines. This incident fits into a broader, ongoing campaign in which threat actors buy or compromise Google Ads accounts to promote cloned DeFi interfaces and wallet front ends, then trick users into connecting wallets and signing malicious approvals. The Security Alliance (SEAL) reports that malicious Google Ads targeting crypto have been a persistent problem, with hundreds of unique phishing ad URLs blocked and major protocols like Uniswap, PancakeSwap, and others routinely impersonated. Prior analyses from security firms such as Check Point Research have documented similar attacks where fake Google Ads for platforms and wallets led directly to wallet-draining incidents worth hundreds of thousands of dollars in aggregate. The current warning matters because it highlights that the threat is active right now on high-traffic DeFi brands, and it underscores that relying on Google search ads to navigate to crypto services is an increasingly risky behavior.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Phishing

Comments