Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Anthropic suspends access to Fable 5, Mythos 5, citing US directive

June 15, 2026

Akash Network rallies 25% – Can AKT bulls push toward $1?

June 15, 2026

Stake Launches its Referral Code SHIMA – 200% Bonus and 5% Cashback for New Users in 2026

June 15, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Phishing scammers now exploiting Google’s infrastructure to target crypto users
Phishing scammers now exploiting Google's infrastructure to target crypto users
Security and Privacy

Phishing scammers now exploiting Google’s infrastructure to target crypto users

April 16, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Phishing scams targeting crypto users have become more advanced, with attackers abusing Google’s infrastructure to conduct highly convincing attacks.

On April 16, Nick Johnson, the founder and lead developer of Ethereum Name Service (ENS), raised concerns over a fresh method cybercriminals use to compromise Gmail accounts and potentially target associated crypto wallets.

How phishing attackers are using Google to their advantage

According to Johnson, the attackers exploit a loophole in Google’s ecosystem that allows them to send phishing emails that appear genuine security alerts from the tech giant itself.

These emails are signed with valid DomainKeys Identified Mail (DKIM) signatures, enabling them to bypass spam filters and appear authentic to recipients.

Once opened, these emails direct users to a counterfeit support portal hosted on a Google subdomain. This fake page prompts victims to log in and upload sensitive documents.

However, Johnson warned that the attackers are likely harvesting credentials, which could compromise Gmail accounts and any services linked to those emails.

The phishing sites are built using Google’s Sites platform, which allows custom scripts and embedded content.

While this flexibility benefits legitimate users, it also allows malicious actors to create convincing phishing portals. Even more concerning is that there’s currently no way to report abuse directly through the Google Sites interface, making it easier for attackers to keep their content online.

He said:

“Google long ago realised that hosting public, user-specified content on google.com is a bad idea, but Google Sites has stuck around. IMO they need to disable scrips and arbitrary embeds in Sites; this is too powerful a phishing vector.”

To further enhance the illusion of legitimacy, the scammers create a Google OAuth application that formats and shares the phishing message. These messages are always complete with structured text and what appears to be contact information for Google Legal Support.

See also  BBVA migrates its crypto custody service to Ripple-owned Metaco’s Harmonize

Google’s response

Johnson reported that he submitted a bug report to Google about this vulnerability.

Still, the search engine giant reportedly stated that the features work as intended and do not constitute a security issue.

Johnson wrote:

“I’ve submitted a bug report to Google about this; unfortunately they closed it as ‘Working as Intended’ and explained that they don’t consider it a security bug.”

Nevertheless, he urged Google to consider limiting script and embedding functionality to help prevent future abuse.

This incident highlights the increasing sophistication of phishing campaigns within the crypto space. According to Scam Sniffer, nearly 6,000 users lost around $6.37 million to phishing scams in March 2025 alone. In the first quarter of the year, 22,654 victims suffered total losses of $21.94 million.

Mentioned in this article



Source link

Crypto Exploiting Googles Infrastructure Phishing Scammers Target users
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Stake Launches its Referral Code SHIMA – 200% Bonus and 5% Cashback for New Users in 2026

June 15, 2026

CLARITY Act Gets New Push as Senator Ties Crypto Rules to US Dollar Power

June 15, 2026

Orbs Launches On-Chain Execution Infrastructure for Institutional Crypto Trading

June 14, 2026

Tennessee Man Indicted for Alleged Crypto Ponzi Scheme That Stole Millions From Investors

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Milady NFTs Underwent the Dogecoin Treatment Following Elon Musk Tweet

May 26, 2023

Dive Into Zara’s Latest Fashion Capsule Collection

May 20, 2023

US SEC Agency Drops Gemini & Tron ($TRX) Lawsuit

February 28, 2025

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Anthropic suspends access to Fable 5, Mythos 5, citing US directive

June 15, 2026

Akash Network rallies 25% – Can AKT bulls push toward $1?

June 15, 2026

Stake Launches its Referral Code SHIMA – 200% Bonus and 5% Cashback for New Users in 2026

June 15, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$65,876.002.19%
  • ethereumEthereum(ETH)$1,721.652.47%
  • tetherTether(USDT)$1.00-0.02%
  • binancecoinBNB(BNB)$617.181.30%
  • usd-coinUSDC(USDC)$1.00-0.02%
  • rippleXRP(XRP)$1.193.26%
  • solanaSolana(SOL)$71.253.60%
  • tronTRON(TRX)$0.3209421.67%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.020.00%
  • HyperliquidHyperliquid(HYPE)$64.947.48%