icon
icon
icon
icon
🏷️$300 Off
🏷️$300 Off

News /

Articles /

Ethereum Founder Warns of Advanced Google Phishing Attack

Coin WorldWednesday, Apr 16, 2025 11:25 pm ET
1min read

The founder and lead developer of Ethereum Name Service (ENS), Nick Johnson, has issued a warning to his followers on X about an advanced phishing attack that mimics google to deceive users into divulging their login credentials.

Johnson detailed the attack in an April 16 post, explaining that it exploits Google’s infrastructure to send a fake alert. This alert informs users that their Google data is being shared with law enforcement due to a subpoena. The phishing email passes Google’s DKIM signature check and appears in the user’s inbox without any warnings, even in the same conversation thread as legitimate security alerts.

The fake subpoena appears to originate from a Google no-reply domain, adding to its legitimacy. Users are given the option to view case materials or protest by clicking a support page link, which is hosted on Google Sites. This tool allows anyone with a Google account to create a site that looks legitimate and is hosted under a trusted Google-owned domain.

Johnson noted that while the Google domain name gives the impression of legitimacy, there are still signs that it is a phishing scam. For instance, the email is forwarded by a private email address, which is a red flag.

In an April 11 report, software firm EasyDMARC explained that the phishing scam works by weaponizing Google Sites. Scammers use the Google OAuth app, where they can input any desired text in the App Name field. They also use a domain via Namecheap that allows them to set no-reply@google account as the From address, with the reply address being anything they choose.

Johnson further explained that because DKIM only verifies the message and its headers, not the envelope, the message passes signature validation and appears as a legitimate message in the user’s inbox.

In response to the issue, a Google spokesperson stated that they are aware of the attack and are taking steps to shut down the mechanism that attackers are using. These protections are expected to be fully deployed soon, which will prevent this method of attack from working in the future.

The spokesperson also emphasized the importance of users adopting two-factor authentication and passkeys, which provide strong protection against phishing campaigns. Google will never ask for private account credentials, including passwords, one-time passwords, or push notifications, nor will they call users.

Comments

Add a public comment...
Post
User avatar and name identifying the post author
Still_Air2415
04/17
Advanced phishing? More like advanced headache. Use that DMARC record to check your domain's security and avoid these sneaky scams.
0
Reply
User avatar and name identifying the post author
1kczulrahyebb
04/17
@Still_Air2415 alright
0
Reply
User avatar and name identifying the post author
I_kove_crackers
04/17
GOOGle's on it, but users still vulnerable.
0
Reply
User avatar and name identifying the post author
BennyBiscuits_
04/17
Phishing attacks getting too sophisticated, man.
0
Reply
User avatar and name identifying the post author
Shinoskay9
04/17
@BennyBiscuits_ yep, it's getting wild.
0
Reply
User avatar and name identifying the post author
CopyGrand7281
04/17
@BennyBiscuits_ True, phishing's getting sneaky.
0
Reply
User avatar and name identifying the post author
cyarui
04/17
2FA and passkeys are a must, folks.
0
Reply
User avatar and name identifying the post author
Anonym0us_amongus
04/17
Phishing attacks getting super sophisticated. We need to stay vigilant, or our crypto bags get compromised.
0
Reply
User avatar and name identifying the post author
No-Explanation7351
04/17
Phishing attacks getting sneaky. Keep those 2FA and passkeys locked down, folks. Google's on it, but better safe than sorry. 🚨
0
Reply
User avatar and name identifying the post author
Super-Implement4739
04/17
I'm all for $TSLA and $AAPL innovation, but let's also spread awareness on these cyber threats. Security is a long-term play, just like stocks.
0
Reply
User avatar and name identifying the post author
Jwavvy9
04/17
Holy!The AAPL stock was in a clear trend, and I made $252 from it!
0
Reply
User avatar and name identifying the post author
pimppapy
04/17
@Jwavvy9 How long were you holding the AAPL stock? Curious about your strategy.
0
Reply
User avatar and name identifying the post author
dritu_
04/17
This phishing scam is like a whack-a-mole game. New tactics pop up, but security improves. Stay vigilant and you'll be fine.
0
Reply
Disclaimer: The news articles available on this platform are generated in whole or in part by artificial intelligence and may not have been reviewed or fact checked by human editors. While we make reasonable efforts to ensure the quality and accuracy of the content, we make no representations or warranties, express or implied, as to the truthfulness, reliability, completeness, or timeliness of any information provided. It is your sole responsibility to independently verify any facts, statements, or claims prior to acting upon them. Ainvest Fintech Inc expressly disclaims all liability for any loss, damage, or harm arising from the use of or reliance on AI-generated content, including but not limited to direct, indirect, incidental, or consequential damages.
You Can Understand News Better with AI.
Whats the News impact on stock market?
Its impact is
fork
logo
AInvest
Aime Coplilot
Invest Smarter With AI Power.
Open App