TL;DR
-
A Hyperliquid user appears to have lost approximately $550,000 in USDC in a phishing attack.
-
The victim reportedly clicked a paid Google ad leading to a fraudulent Hyperliquid website.
-
Blockchain data showed three transfers to addresses linked to the suspected attacker.
A Hyperliquid user appears to have lost approximately $550,000 in USDC after interacting with a phishing website promoted through a paid Google search advertisement.
Darcy, co-founder of digital-asset tracing and recovery company FlashRescue, identified three transfers from the victim’s wallet to addresses allegedly controlled by the attacker.
According to Darcy, the victim reached the fraudulent website after clicking a sponsored Google result impersonating Hyperliquid.
Blockchain Data Reveals Three Suspicious Transfers
Blockchain records shared by Darcy reportedly show that the affected user sent USDC across three separate transactions to addresses associated with the suspected scammer.
🚨 Hyperliquid Google 付费广告钓鱼事件,造成资金损失 约550k
— Darcy 资产救援⛑️ (@DarcyAri) August 13, 2026
攻击者地址:
0x98b2761559A348968C994D9856dCfc96B6f13C55
0x93b6B24DC6E6a1D5d72399e3A35498c4DbA1d6D1
0x6fE314fD4CF845f35fc461eD98e2FB8d9356B566
Google付费广告钓鱼事件频发,请注意保护资产安全 pic.twitter.com/9dVGLUNVJJ
The exact interaction that authorized the transfers remains unclear. However, crypto phishing websites commonly persuade victims to connect their wallets, approve malicious smart contracts or sign transactions that give attackers access to their assets.
Fraudulent platforms are typically designed to resemble legitimate decentralized applications closely. They may copy the genuine website’s branding, interface and wallet-connection process, making it difficult for users to recognize the deception.
Because blockchain transactions are generally irreversible, victims often have limited options for recovering their assets after the funds reach an attacker-controlled address.
The phishing site reportedly appeared as a sponsored result when the user searched for Hyperliquid on Google.
Paid search advertisements can appear above organic results, creating the impression that the advertised website is the platform’s official page. Attackers exploit this placement by purchasing ads containing familiar brand names and linking them to look-alike domains.
The strategy has targeted cryptocurrency users for several years. In 2020, scammers bought search advertisements impersonating decentralized finance platforms such as Balancer and Uniswap.
Those websites were designed to steal private keys or trick users into granting malicious wallet permissions. Similar campaigns have since expanded to other high-value crypto platforms.
Google Suspends Advertiser Behind Alleged Scam
Google confirmed that it had suspended the advertiser’s account after being alerted to the campaign.
The company said it has zero tolerance for scams and claimed that its systems block 99% of advertisements that violate its policies before they become publicly available.
Google also said it removed more than 602 million scam advertisements during the previous year.
Despite these enforcement measures, attackers continue developing methods to bypass automated screening systems. Even a short-lived advertisement can cause significant losses if it reaches a high-value crypto user before being detected.
Crypto security nonprofit Security Alliance, also known as SEAL, reported in April that it had blocked 356 malicious Google advertisement URLs over several weeks.
The campaign included multiple advertisements impersonating Hyperliquid. SEAL said Google subsequently suspended all the advertiser accounts identified in its report.
Hyperliquid is not the only platform targeted by such campaigns. Scammers frequently imitate Ethereum protocols with high total value locked and popular Solana-based applications such as Jupiter, Raydium and Pump.fun.
These platforms are attractive targets because their users routinely connect wallets and authorize transactions, making a fraudulent wallet prompt less likely to seem unusual.
SEAL said some scammers obtain previously approved advertiser accounts through theft or illicit purchases.
Using established accounts may help malicious operators bypass Google’s automated review processes and publish fraudulent advertisements more quickly.
Once an account is suspended, the attackers can move to another compromised profile, domain or advertising campaign. This creates a persistent challenge for search platforms and security researchers attempting to disrupt the scams.
SEAL noted that an advertisement may be live for only a few minutes before attracting its first victim. The potential for a single high-value theft gives criminals an incentive to continue launching new campaigns despite the costs associated with repeated takedowns.
Crypto Users Urged to Verify Website Addresses
The incident highlights the risks of accessing cryptocurrency applications through sponsored search results.
Users can reduce their exposure by bookmarking official websites and checking domain names carefully before connecting a wallet. They should also verify transaction details and permission requests before signing anything.
Hardware wallets and transaction-simulation tools can provide additional warnings, but they cannot fully protect users who approve malicious transactions.
For high-value wallets, separating long-term holdings from accounts used to interact with decentralized applications can limit potential losses if a phishing website succeeds.
Hassan Maishera