Editor's Pick

Fake Google Ad for Hyperliquid Drains About $550,000 From…

A Hyperliquid user appears to have lost approximately $550,000 after interacting with a phishing website promoted through a paid Google search advertisement, highlighting how attackers are increasingly exploiting conventional advertising infrastructure to target cryptocurrency users. The incident was flagged on August 13 by Darcy, co-founder of digital-asset tracing and recovery firm FlashRescue. Blockchain data cited by the security researcher showed funds moving from the affected wallet to three addresses identified as belonging to the attacker.

The transfers totaled approximately 550,019 USDC. The largest was roughly 440,015 USDC, followed by transfers of about 82,503 USDC and 27,501 USDC. Darcy attributed the incident to a malicious paid advertisement appearing in Google search results for Hyperliquid. The advertisement reportedly directed the user to a website impersonating the decentralized trading platform. There is no indication that Hyperliquid itself was hacked or that the incident resulted from a vulnerability in its underlying protocol.

Attackers Are Buying Their Way to the Top of Search

The attack illustrates a particularly dangerous form of cryptocurrency phishing because victims do not necessarily encounter a suspicious unsolicited message. Instead, an investor can deliberately search for a legitimate platform and encounter a malicious sponsored result positioned prominently on the page. The fraudulent site can then imitate the genuine interface and attempt to obtain wallet credentials, malicious signatures or other authorization allowing assets to be transferred. Blockchain records establish the movement of the approximately $550,000, although on-chain data alone cannot independently prove exactly how access was obtained. The connection to the Google advertisement is based on the investigation by FlashRescue.

The incident is also not isolated. In April, crypto security nonprofit Security Alliance, or SEAL, said it had identified and blocked 356 malicious Google advertising URLs during a period of several weeks. Several impersonated Hyperliquid, while other campaigns targeted prominent Ethereum and Solana applications including Jupiter, Raydium and Pump.fun. SEAL said Google subsequently suspended the advertiser accounts identified in its report. Attackers can use compromised or illicitly acquired advertising accounts to evade automated screening systems, while individual malicious advertisements may remain active only briefly before being replaced.

Hyperliquid Has Become a Valuable Phishing Target

The economics behind such attacks are straightforward: increasingly valuable crypto accounts make the advertising expense worthwhile if even a small number of users are deceived. Hyperliquid has become an especially attractive target as its decentralized perpetual-futures ecosystem has expanded. That growth means malicious advertisements impersonating the platform potentially reach traders accustomed to connecting wallets and authorizing high-value transactions. Hyperliquid users have previously faced other impersonation campaigns. In November 2025, on-chain investigator ZachXBT warned about a fake Hyperliquid application appearing on Google Play and identified an address associated with stolen funds.

The latest incident therefore reflects a broader security problem rather than a protocol-specific exploit. For crypto platforms, security increasingly extends beyond smart contracts and blockchain infrastructure. Users can lose assets even when the underlying protocol functions exactly as designed if attackers successfully compromise the interface through which they believe they are accessing it. The roughly $550,000 Hyperliquid-related loss demonstrates that search engines themselves have become part of crypto’s security perimeter — and that a sponsored result can be considerably more dangerous than it appears.