#Crypto

Hyperliquid user reportedly loses $550K in Google ad scam



A Hyperliquid user appears to have lost about $550,000 in USDC on Aug. 13 after interacting with a phishing website promoted through a Google search advertisement, according to FlashRescue co-founder Darcy.

Summary

  • Hyperliquid user reportedly lost 550,019 USDC after transfers reached three addresses reportedly linked to attackers.
  • Google suspended the advertiser after paid search result allegedly directed users toward a phishing site.
  • SEAL blocked over 356 malicious advertising URLs during recent campaigns targeting cryptocurrency applications and wallets.
  • Hyperliquid documentation warns users to verify full URLs and treat unknown wallet activity as compromise.
  • On-chain transfers verify the fund movements, but cannot independently establish that Google advertising caused them.

His post identified three addresses allegedly controlled by the attacker.

On-chain data associated with the reported transaction shows roughly 550,019 USDC was split among the three addresses. The transfers provide evidence that the funds moved, but blockchain records alone cannot establish how the victim was deceived. Darcy attributed the theft to a paid Google advertisement impersonating Hyperliquid. GoPlus Security subsequently identified two of the same addresses in its own warning.

Hyperliquid phishing transfers totaled about 550,019 USDC

The reported transaction split the funds into about 440,015 USDC, 82,503 USDC and 27,501 USDC. The three recipient addresses were 0x98b276…13C55, 0x93b6B2…d6D1 and 0x6fE314…B566.

Those movements are consistent with Darcy’s approximately $550,000 estimate. However, the causal link to the Google advertisement currently rests on the researcher’s attribution and reported victim evidence rather than the blockchain itself. Security Alliance, or SEAL, similarly warns that reliable attribution of losses to individual advertisements requires direct victim evidence and additional indicators of compromise.

Google told The Block that it suspended the advertiser connected to the reported campaign. A spokesperson said the company has “zero tolerance for scams” and said its systems stopped more than 99% of policy violating ads before they ran during 2025. Hyperliquid did not immediately respond to the publication’s request for comment.

Google’s own 2025 Ads Safety report says it blocked or removed more than 8.3 billion ads and suspended 24.9 million advertiser accounts last year. That included 602 million advertisements and four million accounts associated with scams. Those figures cover Google’s global enforcement rather than this Hyperliquid case specifically.

SEAL tracked Hyperliquid impersonations months earlier

SEAL documented the wider campaign in April and said it had blocked more than 356 malicious advertising URLs within several weeks. Its dataset contained 17 Hyperliquid impersonation sites, accounting for about 5% of the 352 entries included in its brand breakdown.

The security group said attackers use hacked or illicitly purchased verified advertiser accounts alongside cloaking and fingerprinting to evade automated checks. Some campaigns place benign looking Google hosted pages in front of malicious content delivered through secondary frames. SEAL advised crypto users to avoid accessing cryptocurrency applications through Google Search and instead use verified bookmarks.

The pattern has already produced other reported losses. As crypto.news previously reported, fake Uniswap advertisements were linked to at least $400,000 in thefts in May. SEAL separately calculated $1.27 million in confirmed and unattributed losses tied to suspected malicious Google advertisements between March 13 and March 30.

In related coverage, a Trezor user reported losing funds after clicking a sponsored phishing result earlier this month. Trezor later warned customers that sponsored search results can imitate its official website and should not automatically be trusted.

No Hyperliquid protocol breach has been identified

Nothing in the available evidence indicates that Hyperliquid’s blockchain or trading protocol itself was breached. The reported attack instead appears to have targeted the user before interaction with the legitimate platform by directing the victim to an impersonating website. This is an inference from the available security reports rather than a Hyperliquid finding.

Hyperliquid’s official support documentation already warns users to check complete website URLs because scammers use similar looking domains. Its support guidance also says unauthorized transactions, missing funds or unknown multisig changes can indicate that a wallet has been compromised.

What happens next

Google has suspended the advertiser identified in the report, while the three recipient addresses remain publicly traceable on-chain. No law enforcement investigation or asset recovery connected to this specific loss had been publicly announced in the sources reviewed as of Aug. 14.

The next verifiable development would be movement from the recipient wallets or identification of an exchange, bridge or other service through which investigators could seek additional information. For now, the approximately $550,000 loss is supported by the reported on-chain transfers, while the claim that a Google advertisement caused the theft remains attributed to FlashRescue’s Darcy.





Source link

Hyperliquid user reportedly loses $550K in Google ad scam

If Apple sends you a push notification

Leave a comment

Your email address will not be published. Required fields are marked *