A Hyperliquid user reportedly lost about $550,000 in USDC after interacting with a phishing website promoted through a Google search advertisement, highlighting the growing risks of crypto-focused search scams.
A Hyperliquid user reportedly lost approximately $550,000 worth of USDC on Aug. 13 after allegedly visiting a fraudulent website promoted through a Google search advertisement.
The incident was reported by Darcy, co-founder of FlashRescue, who identified three wallet addresses that he said were controlled by the attacker. Darcy's report on X
On-chain data shows approximately 550,019 USDC was distributed across three recipient addresses. The blockchain transfers confirm that the funds moved, but blockchain records alone cannot establish how the victim was tricked or whether the Google advertisement directly caused the loss.
According to Darcy's attribution, the victim encountered a paid advertisement impersonating Hyperliquid and subsequently interacted with a phishing website.
$550,019 in USDC moved to three addresses
The reported transaction divided the funds among three addresses in separate transfers.
Approximately:
440,015 USDC
82,503 USDC
27,501 USDC
were sent to three addresses identified in the security report.
The combined amount was approximately 550,019 USDC, consistent with the reported $550,000 loss.
The addresses identified were:
0x98b276…13C55
0x93b6B2…d6D1
0x6fE314…B566
The on-chain movements establish that the USDC was transferred, but they do not independently prove that the transaction resulted from a Google advertisement.
That distinction is important when assessing crypto phishing incidents because attribution generally requires additional evidence from the affected user, browser activity, malicious domains or other indicators of compromise.
Google reportedly suspended the advertiser
Google reportedly told The Block that it had suspended the advertiser associated with the reported campaign.
The company said it has zero tolerance for scams and highlighted its broader advertising enforcement efforts.
Google's 2025 Ads Safety Report said the company blocked or removed more than 8.3 billion advertisements and suspended approximately 24.9 million advertiser accounts during 2025. The company said more than 600 million blocked advertisements were associated with scams. Google 2025 Ads Safety Report
Those figures represent Google's global advertising enforcement and do not establish how many fraudulent advertisements were specifically related to Hyperliquid.
Hyperliquid had not publicly confirmed that its protocol was compromised in connection with the reported incident.
Security researchers have tracked fake Hyperliquid websites
The reported incident is consistent with a wider trend of attackers using paid search advertising to impersonate cryptocurrency platforms.
Security researchers at the Security Alliance, commonly known as SEAL, previously documented campaigns involving malicious advertisements targeting crypto users.
SEAL reported identifying hundreds of malicious advertising URLs and multiple websites impersonating major cryptocurrency brands, including Hyperliquid.
Researchers have warned that attackers can use techniques such as compromised advertiser accounts, cloaking and browser fingerprinting to make malicious campaigns more difficult for advertising platforms to detect.
In some cases, a search result may appear legitimate because the advertisement is displayed above organic results and uses familiar branding.
This creates a particularly dangerous environment for crypto users because a victim may believe they are visiting an official exchange or wallet website when they are actually interacting with an attacker-controlled domain.
Google search ads have been used in other crypto phishing attacks
The Hyperliquid case is not an isolated example of cryptocurrency phishing involving paid search advertisements.
Earlier reports have linked fraudulent Google advertisements to attacks impersonating other crypto platforms.
A separate campaign involving fake Uniswap advertisements was associated with more than $400,000 in reported losses. Other incidents have involved fraudulent advertisements impersonating hardware wallet companies and cryptocurrency services.
The recurring pattern is straightforward: attackers purchase or compromise advertising accounts, create advertisements that resemble legitimate crypto brands and direct users to websites designed to capture wallet credentials or authorize malicious transactions.
For cryptocurrency users, this creates an important security risk because the advertisement itself can appear legitimate even when the destination is not.
Hyperliquid has not been identified as the source of the breach
There is currently no evidence in the reported information that Hyperliquid's blockchain or trading protocol was breached.
Instead, the available evidence points toward a potential phishing attack against the user.
The distinction matters.
A protocol exploit generally involves a vulnerability in smart contracts, consensus infrastructure or application logic. A phishing attack instead attempts to manipulate users into voluntarily revealing information, connecting wallets or approving transactions.
In this case, the reported funds were transferred from the user's wallet to external addresses.
That makes the incident more consistent with a wallet-level compromise or malicious authorization than a direct attack against Hyperliquid itself, although the precise attack method has not been independently established.
Hyperliquid warns users to verify website addresses
Hyperliquid's official support documentation advises users to carefully verify website URLs and remain alert to scams involving similar-looking domains. Hyperliquid Support Documentation
This is particularly important when accessing cryptocurrency platforms through search engines.
A safer approach is to enter the official domain manually, use a trusted bookmark or access the platform through an official application.
Users should also avoid connecting a wallet to unfamiliar websites simply because the site appears at the top of a search page.
Why crypto phishing attacks are particularly dangerous
Unlike traditional card payments, blockchain transactions generally cannot be reversed by the payment network after they have been confirmed.
If a user signs a malicious transaction or transfers stablecoins to an attacker-controlled address, recovering the funds can be extremely difficult.
Attackers therefore have a strong incentive to target users before they reach legitimate crypto platforms.
Search advertisements can be particularly effective because they appear when users are actively looking for a specific service.
Someone searching for Hyperliquid, for example, may be more likely to trust a result that uses the platform's name and branding.
What users should do to avoid crypto search scams
Crypto users can reduce their exposure to these attacks by following several basic precautions:
Do not automatically trust sponsored search results.
Check the complete website domain before connecting a wallet.
Use official bookmarks for exchanges and wallets.
Never enter seed phrases or private keys into websites.
Review wallet transaction requests carefully before signing.
Use hardware wallets or separate wallets for significant holdings where appropriate.
Verify suspicious links through the project's official social channels or documentation.
For high-value transactions, users should take additional time to verify the destination address and the application requesting authorization.
What happens next?
The three recipient addresses remain publicly traceable on the blockchain, meaning investigators can monitor where the stolen USDC moves next.
If the funds are transferred to a centralized exchange, bridge or other identifiable service, investigators could potentially use that information to pursue further action.
However, no publicly confirmed recovery or law enforcement action connected specifically to this reported $550,000 loss had been announced in the information reviewed as of Aug. 14.
For now, the approximately $550,000 USDC transfer is supported by on-chain activity, while the claim that a Google advertisement directly caused the theft remains based on the attribution provided by FlashRescue's Darcy and associated security research.
The incident serves as another warning that crypto users should not assume the first result on a search engine is an official platform.