A Hyperliquid user lost roughly $550,000 in USDC on Aug. 13 after clicking a fraudulent Google ad that directed them to a phishing site impersonating the platform.
Darcy, co-founder of blockchain tracing firm FlashRescue, reported the incident on X and identified three addresses allegedly controlled by the attacker. GoPlus Security subsequently flagged two of the same addresses in its own warning.
On-chain data shows approximately 550,019 USDC was split across three transfers: about 440,015 USDC, 82,503 USDC and 27,501 USDC. The recipient addresses were 0x98b276…13C55, 0x93b6B2…d6D1 and 0x6fE314…B566. Google told The Block it suspended the advertiser connected to the campaign, saying it has "zero tolerance for scams" and that its systems stopped more than 99 percent of policy-violating ads before they ran during 2025.
The incident follows a broader pattern of crypto phishing via sponsored search results. Security Alliance (SEAL) documented 356 malicious advertising URLs earlier this year, including 17 Hyperliquid impersonation sites. SEAL calculated $1.27 million in confirmed and suspected losses tied to malicious Google advertisements between March 13 and March 30 alone.
SEAL said attackers use hacked or illicitly purchased verified advertiser accounts alongside cloaking and fingerprinting to evade automated checks. Some campaigns place benign Google-hosted pages in front of malicious content delivered through secondary frames. The group advised crypto users to avoid accessing crypto applications through Google Search and instead use verified bookmarks.
The pattern has produced other reported losses. Fake Uniswap advertisements were linked to at least $400,000 in thefts in May, and a Trezor user reported losing funds after clicking a sponsored phishing result earlier this month. Trezor warned customers that sponsored search results can imitate its official website.
Nothing in the available evidence indicates that Hyperliquid's blockchain or trading protocol was breached. The attack targeted the user before interaction with the legitimate platform by directing the victim to an impersonating website. Hyperliquid's support documentation warns users to check complete website URLs because scammers use similar-looking domains.
The incident comes as activity on Hyperliquid continues to grow. Active perpetual traders reached a record 263,666 on Aug. 6, up from approximately 150,000 in early January. The HYPE token returned 79.2 percent during the latest quarter, reaching an all-time high of $76.90 on June 16.
Google has suspended the advertiser identified in the report, while the three recipient addresses remain publicly traceable on-chain. No law enforcement investigation or asset recovery connected to this specific loss had been publicly announced as of Aug. 14. The next verifiable development would be movement from the recipient wallets or identification of an exchange or bridge through which investigators could seek additional information.
This article is for informational purposes only and does not constitute investment advice.