Hyperliquid User Loses $550K in Sophisticated Google Ad Scam

Table of Contents

TL;DR

  • A Hyperliquid user appears to have lost about $550,000 in USDC after clicking a malicious Google search ad impersonating the trading platform.
  • Blockchain data linked three transfers from the victim’s wallet to addresses identified as controlled by the attacker.
  • Security Alliance has blocked more than 356 malicious crypto ad URLs, showing that paid search results remain a major phishing risk.

A Hyperliquid user appears to have lost roughly $550,000 in USDC after clicking a fraudulent Google ad that led to a website designed to imitate the trading platform. Crypto security specialist Darcy, co-founder of digital-asset tracing firm FlashRescue, identified the incident through on-chain transactions and linked three transfers to addresses he believes were controlled by the attacker.

The case shows how phishing campaigns are becoming more sophisticated while still exploiting a basic point of user behavior. Search engines often serve as the first place users go when accessing a crypto application, making a sponsored result capable of appearing more trustworthy than an unfamiliar direct link.

According to blockchain security organization Security Alliance, also known as SEAL, attackers have repeatedly used Google Ads to impersonate major DeFi platforms and crypto services. SEAL blocked more than 356 malicious advertising URLs during several weeks in March and April, including multiple domains imitating Hyperliquid.

Hyperliquid Becomes A Target For Advanced Phishing

The attackers do not necessarily need to compromise the underlying trading platform. Instead, they reproduce the interface users expect to see and attempt to convince visitors to connect a wallet, approve a transaction or disclose sensitive information.

SEAL found that criminals can use compromised advertiser accounts or accounts obtained through illicit markets to bypass parts of automated advertising checks. Some campaigns also use cloaking and hidden technical layers that show benign content to security systems while delivering malicious pages to selected visitors.

The strategy has affected a broad range of crypto services. SEAL has identified campaigns targeting Uniswap, PancakeSwap, CoW Swap, Morpho Finance, Jupiter, Raydium, Pump.fun and Hyperliquid. Between March 13 and March 30, the organization linked Google-ad phishing activity to approximately $1.27 million in losses.

A Hyperliquid user appears to have lost about $550,000 in USDC after clicking a malicious Google search ad impersonating the trading platform.

For crypto users, the episode reinforces an important advantage of blockchain transparency. Once funds move on-chain, investigators can follow transactions, identify related wallets and potentially connect multiple incidents to the same infrastructure.

The incident does not indicate a failure of Hyperliquid’s trading infrastructure itself. Instead, it highlights how attackers can exploit the broader digital environment surrounding established crypto brands.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews