Tuesday, January 13, 2026
No Result
View All Result
The Crypto HODL
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
No Result
View All Result
The Crypto HODL
No Result
View All Result

Phishing scammers now exploiting Google’s infrastructure to target crypto users

April 17, 2025
in Scam Alert
Reading Time: 2 mins read
0 0
A A
0
Home Scam Alert
Share on FacebookShare on Twitter



Phishing scams concentrating on crypto customers have grow to be extra superior, with attackers abusing Google’s infrastructure to conduct extremely convincing assaults.

On April 16, Nick Johnson, the founder and lead developer of Ethereum Title Service (ENS), raised considerations over a contemporary methodology cybercriminals use to compromise Gmail accounts and probably goal related crypto wallets.

How phishing attackers are utilizing Google to their benefit

In response to Johnson, the attackers exploit a loophole in Google’s ecosystem that permits them to ship phishing emails that seem real safety alerts from the tech big itself.

These emails are signed with legitimate DomainKeys Recognized Mail (DKIM) signatures, enabling them to bypass spam filters and seem genuine to recipients.

As soon as opened, these emails direct customers to a counterfeit help portal hosted on a Google subdomain. This pretend web page prompts victims to log in and add delicate paperwork.

Nonetheless, Johnson warned that the attackers are possible harvesting credentials, which may compromise Gmail accounts and any companies linked to these emails.

The phishing websites are constructed utilizing Google’s Websites platform, which permits customized scripts and embedded content material.

Whereas this flexibility advantages authentic customers, it additionally permits malicious actors to create convincing phishing portals. Much more regarding is that there’s presently no method to report abuse straight by way of the Google Websites interface, making it simpler for attackers to maintain their content material on-line.

He stated:

“Google way back realised that internet hosting public, user-specified content material on google.com is a foul concept, however Google Websites has caught round. IMO they should disable scrips and arbitrary embeds in Websites; that is too highly effective a phishing vector.”

To additional improve the phantasm of legitimacy, the scammers create a Google OAuth utility that codecs and shares the phishing message. These messages are at all times full with structured textual content and what seems to be contact info for Google Authorized Assist.

Google’s response

Johnson reported that he submitted a bug report back to Google about this vulnerability.

Nonetheless, the search engine big reportedly said that the options work as supposed and don’t represent a safety problem.

Johnson wrote:

“I’ve submitted a bug report back to Google about this; sadly they closed it as ‘Working as Meant’ and defined that they don’t take into account it a safety bug.”

Nonetheless, he urged Google to contemplate limiting script and embedding performance to assist stop future abuse.

This incident highlights the rising sophistication of phishing campaigns inside the crypto house. In response to Rip-off Sniffer, practically 6,000 customers misplaced round $6.37 million to phishing scams in March 2025 alone. Within the first quarter of the yr, 22,654 victims suffered whole losses of $21.94 million.

Talked about on this article

Newest Alpha Market Report



Source link

Tags: cryptoExploitingGooglesInfrastructurephishingScammersTargetusers
Previous Post

Local Chinese Governments Cash In on Confiscated Crypto

Next Post

Outlier Ventures And LifeX Ventures Unveil Inaugural Cohort For Post Web Base Camp Accelerator Program

Related Posts

How global sanctions are reshaping illicit crypto activity
Scam Alert

How global sanctions are reshaping illicit crypto activity

January 12, 2026
Truebit protocol hack exposes DeFi security risks as TRU token collapses
Scam Alert

Truebit protocol hack exposes DeFi security risks as TRU token collapses

January 10, 2026
Fake MetaMask 2FA phishing scam uses polished design to steal wallet seed phrases
Scam Alert

Fake MetaMask 2FA phishing scam uses polished design to steal wallet seed phrases

January 6, 2026
SEC filings reveal the multi-million dollar trap hiding inside ‘exclusive’ WhatsApp crypto investment clubs
Scam Alert

SEC filings reveal the multi-million dollar trap hiding inside ‘exclusive’ WhatsApp crypto investment clubs

January 8, 2026
Fake Zoom malware scam tied to North Korean hackers targets crypto users
Scam Alert

Fake Zoom malware scam tied to North Korean hackers targets crypto users

December 15, 2025
Do Kwon faces sentencing in New York as TerraUSD collapse returns to spotlight
Scam Alert

Do Kwon faces sentencing in New York as TerraUSD collapse returns to spotlight

December 11, 2025
Next Post
Outlier Ventures And LifeX Ventures Unveil Inaugural Cohort For Post Web Base Camp Accelerator Program

Outlier Ventures And LifeX Ventures Unveil Inaugural Cohort For Post Web Base Camp Accelerator Program

OKX Relaunches in US with Staged Rollout

OKX Relaunches in US with Staged Rollout

Fake MFSA Letters Demand Fines From Bitcoin and Ethereum Traders, Regulator Warns

Fake MFSA Letters Demand Fines From Bitcoin and Ethereum Traders, Regulator Warns

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Twitter Instagram LinkedIn Telegram RSS
The Crypto HODL

Find the latest Bitcoin, Ethereum, blockchain, crypto, Business, Fintech News, interviews, and price analysis at The Crypto HODL

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Mining
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Videos
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2023 The Crypto HODL.
The Crypto HODL is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
Crypto Marketcap

Copyright © 2023 The Crypto HODL.
The Crypto HODL is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In