Skip to main content
BTC / USDT——ETH / USDT——SOL / USDT——BNB / USDT——XRP / USDT——DOGE / USDT——TON / USDT——AVAX / USDT——LINK / USDT——ADA / USDT——TRX / USDT——DOT / USDT——BTC / USDT——ETH / USDT——SOL / USDT——BNB / USDT——XRP / USDT——DOGE / USDT——TON / USDT——AVAX / USDT——LINK / USDT——ADA / USDT——TRX / USDT——DOT / USDT——
Preise
cryptoAug 14, 2026, 5:47 AM

Fake Google Ad for Hyperliquid Drains About $550,000 From…

A Hyperliquid trader lost roughly $550,000 after visiting a phishing site promoted through a Google search ad, according to FlashRescue. No protocol exploit was involved.

On August 13, Darcy, co-founder of crypto asset-tracing and recovery firm FlashRescue, flagged an incident in which a Hyperliquid user appears to have lost approximately $550,000 after interacting with a phishing website promoted through a paid Google Search advertisement. Blockchain records cited by the security researcher show funds moving from the affected wallet to three addresses identified as belonging to the attacker.

The transfers totaled roughly 550,019 USDC. The largest single transfer was about 440,015 USDC, followed by transfers of approximately 82,503 USDC and 27,501 USDC. Darcy attributed the incident to a malicious paid advertisement that appeared in Google search results for Hyperliquid and reportedly redirected the user to a lookalike site impersonating the decentralized trading platform. There is no indication that Hyperliquid itself was compromised or that the loss resulted from a vulnerability in its underlying protocol.

This attack highlights a particularly deceptive form of crypto phishing because victims are not lured by an unsolicited message. Instead, an investor searching for a legitimate platform may encounter a malicious sponsored result positioned prominently at the top of the search page. The fraudulent site can then imitate the genuine interface and attempt to obtain wallet credentials, malicious signatures, or other authorization that would allow assets to be moved.

The incident is not isolated. In April, crypto security nonprofit Security Alliance (SEAL) said it had identified and blocked 356 malicious Google advertising URLs over a period of several weeks. Several of those campaigns impersonated Hyperliquid, while others targeted prominent Ethereum and Solana applications including Jupiter, Raydium, and Pump.fun. SEAL noted that Google later suspended the advertiser accounts identified in its report. Attackers often use compromised or illicitly acquired advertising accounts to evade automated screening, and individual malicious ads may remain live only briefly before being swapped out.

Hyperliquid has become an especially attractive target as its decentralized perpetual-futures ecosystem grows. The platform's popularity means impersonation ads can reach traders who are accustomed to connecting wallets and authorizing high-value transactions. In November 2025, on-chain investigator ZachXBT warned about a fake Hyperliquid application appearing on Google Play and identified an address tied to stolen funds. The latest loss underscores that security for crypto platforms now extends beyond smart contracts and blockchain infrastructure. Even when the protocol functions exactly as designed, users can lose assets if attackers compromise the interface they believe they are using. The roughly $550,000 theft demonstrates that search engines themselves have become part of crypto's security perimeter — and that a sponsored result can be far more dangerous than it appears.

Source: FinanceFeeds