
A Hyperliquid user reportedly lost approximately $550,019 in USDC after falling victim to a sophisticated phishing scam that exploited Google search advertisements. According to reports from Wu Blockchain and crypto security specialist Darcy from FlashRescue, the attack involved malicious ads that appeared at the top of Google search results, luring users to a fraudulent website that mimicked Hyperliquid's official platform. The transaction split the funds into three separate transfers: 440,015 USDC, 82,503 USDC, and 27,501 USDC, with the funds reaching three addresses allegedly controlled by attackers. The three recipient addresses were identified as 0x98b2761559A348968C994D9856dCfc96B6f13C55, 0x93b6B24DC6E6a1D5d72399e3A35498c4DbA1d6D1, and 0x6fE314fD4CF845f35fc461eD98e2FB8d9356B566. The exact interaction that authorized the transfers remains unclear, though crypto phishing websites commonly persuade victims to connect their wallets, approve malicious smart contracts or sign transactions that give attackers access to their assets.
Google has taken action against the advertiser responsible for the reported campaign. As reported by The Block, a Google spokesperson confirmed that the company has 'zero tolerance for scams' and that its systems stopped more than 99% of policy violating ads before they ran during 2025. The company removed more than 602 million scam advertisements during the previous year and suspended the advertiser connected to the reported campaign after a paid search result allegedly directed users toward the phishing site. According to Wu Blockchain, the scammers purchased Google search ads that displayed Hyperliquid's official domain name or a look-alike URL, with users being redirected to a phishing site designed to steal login credentials or trick users into approving malicious transactions. Despite these enforcement measures, attackers continue developing methods to bypass automated screening systems, with even short-lived advertisements causing significant losses if they reach high-value crypto users before detection.
The Hyperliquid incident follows a concerning pattern of phishing attacks targeting major crypto platforms. On August 7, 2026, Trezor issued a statement regarding an increase in phishing websites impersonating its brand, with some appearing in sponsored Google search results. A Trezor user reported that the top sponsored Google result for the search term "Trezor wallet" led to a phishing site, though this campaign was separate from a recent data breach at Trezor's third-party shipping provider ShipMonk that exposed personal information of 13,689 customers. In July, a crypto user lost $999,999 in USDT after signing a phishing token approval on Ethereum, according to Web3 anti-scam firm Scam Sniffer. Unlike attacks that exploit smart-contract approvals, search-ad phishing attempts target users before they interact with legitimate platforms, with fraudulent advertisements directing users to cloned websites designed to collect login credentials, wallet information or transaction approvals. The Hyperliquid case demonstrates how attackers are increasingly using social engineering rather than technological breaches to target users.
According to Woofun AI analysis, the attack's sophistication lies in its ability to mimic Hyperliquid's official platform with such precision that even experienced Web3 participants struggled to distinguish the fake from genuine platform. The vulnerability is particularly concerning given Hyperliquid's nature as a decentralized exchange (DEX) focused on high-speed derivatives trading, where users are conditioned to act rapidly under pressure. This incident reflects a broader industry trend where cybercriminals increasingly abuse search engine advertising to target decentralized finance (DeFi) protocols, with SEAL having blocked more than 356 malicious advertising URLs within several weeks, including 17 Hyperliquid impersonation sites accounting for about 5% of entries in their brand breakdown. The $550,019 loss serves as a stark reminder that social engineering remains a primary threat vector for Hyperliquid users and the wider ecosystem, marking a significant escalation in phishing tactic sophistication targeting decentralized platforms.
Despite the significant loss, Hyperliquid's official support documentation indicates no breach of the platform's blockchain or trading protocol. As reported by The Block, nothing in the available evidence indicates that Hyperliquid's legitimate platform was compromised. The reported attack instead appears to have targeted the user before interaction with the legitimate platform by directing the victim to an impersonating website. Hyperliquid's support guidance already warns users to verify complete website URLs and treat unknown wallet activity as compromise. To protect themselves, users should always type the official URL directly into their browser or use a saved bookmark, double-check the URL in the address bar before entering credentials, enable browser extensions that block sponsored ads, use hardware wallets, and verify transaction details on-chain when possible. For crypto users, the episode reinforces an important advantage of blockchain transparency - once funds move on-chain, investigators can follow transactions, identify related wallets and potentially connect multiple incidents to the same infrastructure. However, because blockchain transactions are generally irreversible, victims often have limited options for recovering their assets after the funds reach an attacker-controlled address.