← Radar

Incident case file

Sign in to watch

Uniswap-Impersonation Google Ads Phishing (AngelFerno Drainer)

Incident date May 25, 2026

0 views

ActiveEthereumPhishing / wallet-drainer kit (Google Ads)Cluster: UNI-PHISH-2026-05

Estimated loss

$400K

Victims identified

10
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Attacker: Attacker wallet 1: 0x37925684BA178821b4436E06e67f5dBD6cfA49Bb. Attacker wallet 2: 0x2fC25F46cC49D226eF92E9A7665f3d2821F3c5E2. Drainer kit: AngelFerno (scam-as-a-service).

Funds moved to: Stolen tokens consolidated toward 0x66a9893cC07D... (PAXG, Mog, XEN, SpaceX, NMT, Ouroboros) and 0x7f54f05635... (USDC ~$18K, USDT ~$5K, Rollblock, wZNN). About $49,382 of value is traceable across the two observed wallets (many stolen tokens are illiquid / shown at $0; these two wallets are a subset of the broader AngelFerno campaign). In parallel the wallets emit address-poisoning spam: fake 'ĖTḨ'/'EṬH' Unicode tokens of 50 units to 0xdef... addresses ($0 value, ignore).
Attacker wallets: 0x37925684BA178821b4436E06e67f5dBD6cfA49Bb and 0x2fC25F46cC49D226eF92E9A7665f3d2821F3c5E2 (per @b_block_oficial, 25 May). Cash-out / consolidation: 0x66a9893cC07D... and 0x7f54f05635.... Across the two wallets, 18 unique 'From' addresses were observed; 6 with material (>$1) traceable value: 0xcaefe3e2891473e1ef94866a7cc8d0961598f43e (~$23,545, incl. PAXG $21K), 0x92457e54b2647341d5162eee7c6fda734e55c3f9 (~$17,954, incl. USDC $17.8K), 0xb539b40793171211dca8834da044fc14bce64bdc (

Timeline: Publicly flagged on 25 May 2026 by on-chain analyst b-block, this is a wallet-drainer phishing campaign using sponsored Google Search ads that impersonate Uniswap (sometimes via Cyrillic/Punycode lookalike domains). A victim clicks the sponsored result above the legitimate uniswap.org link, connects a wallet to a cloned UI, and signs an unlimited token approval; the AngelFerno scam-as-a-service drainer then empties the wallet. On-chain activity on the two identified attacker wallets (0x3792...49Bb, 0x2fC2...c5E2) runs from 12 May to 29 May 2026 -- a continuous campaign that straddles the 23-29 May window, with the public alert and a visible peak on 25 May. The largest observed inflows include PAXG ~$21K (21 May), USDC ~$17.8K (24 May), USDT ~$5.1K (12 May) and Mog ~$1.7K (22 May). Stolen assets are consolidated toward 0x66a9893cC07D... and 0x7f54f05635.... SEAL had previously reported $1.27M lost between 13-30 March 2026 from the same broader Google Ads phishing wave, and described a steady weekly volume of attacker-deployed ads for over a year. b-block put the tracked loss at >=$400K (the two wallets together held ~146 ETH, ~$306K, at tracking time); the $400K tier-1 figure is retained, while only ~$49K is directly USD-traceable on the two observed wallets because many drained tokens are illiquid and because this is a subset of a larger multi-wallet operation. ZachXBT publicly called for criminal liability for Google executives. The campaign remains active; recovery: 0%.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)