Loading prices…
🩸BEARISH

Hyperliquid user loses $550K in Google ad phishing attack

The scam fits a pattern: crypto security nonprofit SEAL blocked 356 malicious Google ad URLs in April alone, several impersonating Hyperliquid.

A Hyperliquid user lost roughly $550,000 in USDC after clicking a paid Google search ad that redirected to a look-alike site impersonating the protocol. Darcy, co-founder of digital-asset tracing firm FlashRescue, posted on-chain data appearing to show three transfers from the victim's wallet to addresses he identified as attacker-controlled. Google confirmed it suspended the advertiser behind the campaign, citing a policy of blocking 99% of policy-violating ads before they run.

Why it matters

The flow is not novel. Paid search ads have impersonated crypto front-ends since at least 2020, when look-alike pages for Balancer and Uniswap were used to harvest private keys and malicious wallet approvals. The recurring pattern shows that for high-TVL protocols, the cheapest attack vector is often not breaking the protocol itself but tricking a user into handing over access. In April alone, crypto security nonprofit SEAL said it blocked 356 malicious Google ad URLs, several impersonating Hyperliquid, and reported every advertiser account to Google for suspension.

Market impact

The dollar figure is small relative to the multi-billion TVL on Hyperliquid, but the exposure is structural. Scammers systematically rotate through high-TVL targets on Ethereum and Solana, including Jupiter, Raydium and Pump.fun, according to SEAL. Attackers often run on compromised or illicitly purchased advertiser accounts, letting an ad stay live only minutes before it finds its first victim, and high-value losses motivate that persistence regardless of takedown speed. For traders routing size through Hyperliquid, the read is to bookmark the protocol's canonical domain and treat any search-result link as suspect.

Related tokens
$HYPE $USDC

Frequently asked questions

  1. How did the Hyperliquid user lose $550,000?

    A paid Google search ad redirected them to a look-alike site impersonating Hyperliquid. The user signed a malicious transaction, and roughly $550,000 in USDC was moved to attacker-controlled addresses across three on-chain transfers.

  2. Who confirmed the phishing tactic?

    Darcy, co-founder of digital-asset tracing firm FlashRescue, posted on-chain data showing the transfers. Google said it had suspended the advertiser behind the campaign.

  3. How often does this phishing tactic target Hyperliquid?

    Crypto security nonprofit SEAL said it blocked 356 malicious Google ad URLs in April, several of which impersonated Hyperliquid. Hyperliquid did not immediately respond to a request for comment.

  4. Why are paid Google ads a recurring crypto phishing vector?

    Scammers buy search ads impersonating high-TVL protocols on Ethereum and Solana, including Hyperliquid, Jupiter, Raydium and Pump.fun. The ads sometimes stay live only minutes before finding their first victim, and high-value losses keep attackers deploying new ones.

  5. What should Hyperliquid traders do to avoid this?

    Bookmark the protocol's canonical domain and treat any search-result link as suspect. Search-based discovery is structurally weak, so any route that bypasses the results page cuts the attack surface.

Source attribution
Aggregated from TheBlock · Verified · Last refreshed 6h ago
Open original →