Official Wallsec emails only ever come from an @wallsec.co.uk address.
← All daily briefings

Recognising Malicious Search Advertisements and Spoofed Cryptocurrency Web Applications

Fraudulent search results and spoofed web portals frequently trick users into entering sensitive credentials or connecting active wallets to predatory software. Verifying domain integrity and maintaining segregated browsing environments significantly reduces exposure to credential theft and asset loss.

  • Inspect destination URLs carefully before interacting with cryptocurrency portals, as sponsored search engine listings frequently redirect users to typo-squatted domains engineered to harvest credentials or manipulate connected software.
  • Bookmark authentic platform addresses directly rather than navigating via search engine queries, and avoid using search-promoted sponsored links when accessing custodial exchange accounts, decentralised services, or personal wallet management interfaces.
  • If account credentials have been entered on a suspected phishing portal, immediately change passwords, invalidate active sessions, and notify the compliance team of the relevant exchange to freeze trading permissions.
  • Report deceptive domains and associated financial losses directly to Action Fraud and your bank, providing exact destination URLs and transfer hashes to assist investigators in establishing onchain destination clusters.

Written by the Wallsec investigations team. General information only, not legal or financial advice.

Need a case reviewed?

Tell us what happened and we will say honestly whether the onchain data supports a trace.

Request a case review