Close Menu
Cryphedge.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Altcoins
  • Scams
  • Blockchain
  • Regulations
  • Trading
Facebook X (Twitter) Instagram
Cryphedge.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Altcoins
  • Scams
  • Blockchain
  • Regulations
  • Trading
Cryphedge.com
Home » Phishing scammers now exploiting Google’s infrastructure to target crypto users
Phishing scammers now exploiting Google’s infrastructure to target crypto users

Phishing scammers now exploiting Google’s infrastructure to target crypto users

April 16, 20253 Mins ReadNo Comments Scams
Share
Facebook Twitter LinkedIn Pinterest Email

Phishing scams targeting crypto users have become more advanced, with attackers abusing Google’s infrastructure to conduct highly convincing attacks.

On April 16, Nick Johnson, the founder and lead developer of Ethereum Name Service (ENS), raised concerns over a fresh method cybercriminals use to compromise Gmail accounts and potentially target associated crypto wallets.

How phishing attackers are using Google to their advantage

According to Johnson, the attackers exploit a loophole in Google’s ecosystem that allows them to send phishing emails that appear genuine security alerts from the tech giant itself.

These emails are signed with valid DomainKeys Identified Mail (DKIM) signatures, enabling them to bypass spam filters and appear authentic to recipients.

Once opened, these emails direct users to a counterfeit support portal hosted on a Google subdomain. This fake page prompts victims to log in and upload sensitive documents.

However, Johnson warned that the attackers are likely harvesting credentials, which could compromise Gmail accounts and any services linked to those emails.

The phishing sites are built using Google’s Sites platform, which allows custom scripts and embedded content.

While this flexibility benefits legitimate users, it also allows malicious actors to create convincing phishing portals. Even more concerning is that there’s currently no way to report abuse directly through the Google Sites interface, making it easier for attackers to keep their content online.

He said:

“Google long ago realised that hosting public, user-specified content on google.com is a bad idea, but Google Sites has stuck around. IMO they need to disable scrips and arbitrary embeds in Sites; this is too powerful a phishing vector.”

To further enhance the illusion of legitimacy, the scammers create a Google OAuth application that formats and shares the phishing message. These messages are always complete with structured text and what appears to be contact information for Google Legal Support.

Google’s response

Johnson reported that he submitted a bug report to Google about this vulnerability.

Still, the search engine giant reportedly stated that the features work as intended and do not constitute a security issue.

Johnson wrote:

“I’ve submitted a bug report to Google about this; unfortunately they closed it as ‘Working as Intended’ and explained that they don’t consider it a security bug.”

Nevertheless, he urged Google to consider limiting script and embedding functionality to help prevent future abuse.

This incident highlights the increasing sophistication of phishing campaigns within the crypto space. According to Scam Sniffer, nearly 6,000 users lost around $6.37 million to phishing scams in March 2025 alone. In the first quarter of the year, 22,654 victims suffered total losses of $21.94 million.

Mentioned in this article
Latest Alpha Market Report

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
cryphedge

Related Posts

Chinese industry group warns Web3 and DeFi high-return deals hide classic Ponzi engines

July 10, 2025

Scam targets dormant Bitcoin wallets with fake legal notice

July 8, 2025

Crypto firms paid $2.7M monthly to North Korean workers

July 2, 2025

Bybit and North Korean hackers headline $2.1 billion crypto hacks in H1

June 27, 2025
Add A Comment

Comments are closed.

Editors Picks

Urgent appeal to help defend Tornado Cash’s Roman Storm and the right to financial privacy

July 13, 2025

Snorter Token Surges While BlockDAG’s $0.0016 Offer Ends Soon

July 13, 2025

Pundit Claims Selling XRP at $10 May Be a ‘Once-in-a-Lifetime’ Regret

July 13, 2025

High-Leverage Crypto Trader James Wynn Deletes X Account After Nine-Digit Losses

July 13, 2025
About

cryphedge is an online news portal that aims to share the latest crypto news, bitcoin, altcoin, blockchain, nft news, regulation, trading, crypto scams and much more stuff.

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Ethereum (ETH) Price Under Pressure: Can Bulls Defend $1,500 or Is a Deeper Decline Imminent?

April 10, 2025

Cardano Network Activity Surges Past 111 Million — Will ADA Follow With a Price Spike?

July 6, 2025

Don’t Ignore These 3 Bear Market Facts

July 12, 2025
Subscribe
Please enable JavaScript in your browser to complete this form.
Loading
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$118,964.001.46%
  • ethereumEthereum(ETH)$2,987.262.14%
  • rippleXRP(XRP)$2.844.93%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$692.551.56%
  • solanaSolana(SOL)$162.361.91%
  • usd-coinUSDC(USDC)$1.000.00%
  • dogecoinDogecoin(DOGE)$0.2005682.98%
  • tronTRON(TRX)$0.3030790.91%
  • staked-etherLido Staked Ether(STETH)$2,984.912.03%
  • cardanoCardano(ADA)$0.745.97%
  • HyperliquidHyperliquid(HYPE)$48.845.02%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$118,671.001.31%
  • stellarStellar(XLM)$0.46923223.13%
  • Wrapped stETHWrapped stETH(WSTETH)$3,607.872.23%
  • suiSui(SUI)$3.483.60%
  • chainlinkChainlink(LINK)$15.805.78%
  • bitcoin-cashBitcoin Cash(BCH)$508.780.85%
  • hedera-hashgraphHedera(HBAR)$0.23775422.22%
  • avalanche-2Avalanche(AVAX)$21.464.86%
  • leo-tokenLEO Token(LEO)$9.03-0.58%
  • Wrapped eETHWrapped eETH(WEETH)$3,200.662.04%
  • shiba-inuShiba Inu(SHIB)$0.0000132.14%
  • WETHWETH(WETH)$2,987.042.04%
  • the-open-networkToncoin(TON)$2.990.39%
  • litecoinLitecoin(LTC)$95.994.10%
  • USDSUSDS(USDS)$1.00-0.01%
  • whitebitWhiteBIT Coin(WBT)$46.200.56%
  • Binance Bridged USDT (BNB Smart Chain)Binance Bridged USDT (BNB Smart Chain)(BSC-USD)$1.000.03%
  • moneroMonero(XMR)$337.572.77%
  • polkadotPolkadot(DOT)$4.034.67%
  • Coinbase Wrapped BTCCoinbase Wrapped BTC(CBBTC)$118,974.001.44%
  • Ethena USDeEthena USDe(USDE)$1.00-0.04%
  • pepePepe(PEPE)$0.0000123.16%
  • uniswapUniswap(UNI)$8.593.45%
  • bitget-tokenBitget Token(BGB)$4.400.87%
  • aaveAave(AAVE)$310.853.91%
  • BittensorBittensor(TAO)$395.234.01%
  • daiDai(DAI)$1.000.02%
  • Pi NetworkPi Network(PI)$0.4698152.42%
  • crypto-com-chainCronos(CRO)$0.1074907.09%
  • aptosAptos(APT)$5.015.36%
  • nearNEAR Protocol(NEAR)$2.564.73%
  • Ethena Staked USDeEthena Staked USDe(SUSDE)$1.180.16%
  • internet-computerInternet Computer(ICP)$5.514.83%
  • okbOKB(OKB)$48.860.97%
  • OndoOndo(ONDO)$0.915.02%
  • Jito Staked SOLJito Staked SOL(JITOSOL)$197.261.83%
  • ethereum-classicEthereum Classic(ETC)$18.573.36%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • mantleMantle(MNT)$0.708.83%
  • kaspaKaspa(KAS)$0.0867655.26%
  • algorandAlgorand(ALGO)$0.26420122.88%
  • sUSDSsUSDS(SUSDS)$1.060.05%
  • EthenaEthena(ENA)$0.3492799.48%
  • USD1USD1(USD1)$1.00-0.05%
  • cosmosCosmos Hub(ATOM)$4.734.00%
  • vechainVeChain(VET)$0.0248516.52%
  • polygon-ecosystem-tokenPOL (ex-MATIC)(POL)$0.2342615.19%
  • bonkBonk(BONK)$0.0000276.06%
  • arbitrumArbitrum(ARB)$0.4161696.15%
  • render-tokenRender(RENDER)$3.807.17%
  • fasttokenFasttoken(FTN)$4.48-0.22%
  • Official TrumpOfficial Trump(TRUMP)$9.661.46%
  • Pudgy PenguinsPudgy Penguins(PENGU)$0.03059533.48%
  • fetch-aiArtificial Superintelligence Alliance(FET)$0.737.00%
  • gatechain-tokenGate(GT)$15.80-1.10%
  • worldcoin-wldWorldcoin(WLD)$1.074.86%
  • sei-networkSei(SEI)$0.3250252.32%
  • Binance-Peg WETHBinance-Peg WETH(WETH)$2,987.402.09%
  • filecoinFilecoin(FIL)$2.593.09%
  • Lombard Staked BTCLombard Staked BTC(LBTC)$118,459.001.15%
  • SkySky(SKY)$0.0787141.19%
  • quant-networkQuant(QNT)$114.923.54%
  • Jupiter Perpetuals Liquidity Provider TokenJupiter Perpetuals Liquidity Provider Token(JLP)$4.730.96%
  • Binance Staked SOLBinance Staked SOL(BNSOL)$172.531.82%
  • JupiterJupiter(JUP)$0.518.33%
  • SPX6900SPX6900(SPX)$1.583.73%
  • kucoin-sharesKuCoin(KCS)$11.430.42%
  • USDtbUSDtb(USDTB)$1.00-0.05%
  • first-digital-usdFirst Digital USD(FDUSD)$1.00-0.17%
  • Kelp DAO Restaked ETHKelp DAO Restaked ETH(RSETH)$3,130.442.09%
  • rocket-pool-ethRocket Pool ETH(RETH)$3,405.022.13%
  • USDT0USDT0(USDT0)$1.000.12%
  • CelestiaCelestia(TIA)$1.923.90%
  • FartcoinFartcoin(FARTCOIN)$1.293.37%
  • xdce-crowd-saleXDC Network(XDC)$0.07934013.91%
  • nexoNEXO(NEXO)$1.281.36%
  • StoryStory(IP)$4.27-1.64%
  • injective-protocolInjective(INJ)$12.664.32%
  • blockstackStacks(STX)$0.808.99%
  • flare-networksFlare(FLR)$0.0173352.78%
  • SonicSonic(S)$0.3663206.42%
  • optimismOptimism(OP)$0.663.93%
  • Mantle Staked EtherMantle Staked Ether(METH)$3,204.102.10%
  • Virtuals ProtocolVirtuals Protocol(VIRTUAL)$1.731.62%
  • StakeWise Staked ETHStakeWise Staked ETH(OSETH)$3,138.512.13%
  • Solv Protocol BTCSolv Protocol BTC(SOLVBTC)$118,785.001.36%
  • Polygon Bridged USDT (Polygon)Polygon Bridged USDT (Polygon)(USDT)$1.00-0.01%
  • dogwifhatdogwifhat(WIF)$1.027.01%