Fake Hyperliquid Google Ad Drains $550K From Crypto User

A Hyperliquid user reportedly lost $550,000 in USDC after clicking a fake Google ad.

Hyperliquid

A Hyperliquid user lost roughly $550,000 in USDC after clicking a malicious Google search advertisement that directed them to a website impersonating the crypto trading platform.

FlashRescue co-founder Darcy reported the incident on Aug. 13 and identified three addresses allegedly controlled by the attacker. Blockchain data showed approximately 550,019 USDC moving to the addresses, including transfers of roughly 440,015 USDC, 82,503 USDC and 27,501 USDC.

The transfers confirm that the funds moved, but do not independently prove just how the victim was deceived. The connection to the fraudulent Google advertisement comes from Darcy's investigation and reported victim evidence.

Google has since suspended the advertiser associated with the campaign. The company explained that it has “zero tolerance for scams” and said its systems prevented more than 99% of policy-violating advertisements from running in 2025. Google separately reported removing or blocking more than 8.3 billion ads last year, including 602 million linked to scams.

Blog

Blog post from Google

Hyperliquid was already being impersonated in Google Ads

The attack appears to be part of a campaign targeting crypto users through sponsored search results. Security Alliance, or SEAL, documented 356 malicious advertising URLs earlier this year, including 17 websites impersonating Hyperliquid. 

The organization said malicious Google Ads have been deployed at a steady rate for more than a year, with attackers frequently switching between major DeFi brands.

Some campaigns use hacked or illegally purchased verified advertiser accounts alongside cloaking systems that are designed to fool automated security checks. SEAL found attackers using trusted Google-hosted pages as an initial layer before loading malicious content through secondary frames. This allows the page shown to security systems to differ from what a targeted victim receives.

The organization has also noticed crypto drainers using browser-based JavaScript to persuade victims to sign malicious transactions. However, there is currently no public evidence establishing which drainer technology, if any, was used in the latest Hyperliquid incident.

SEAL recorded about $1.27 million in confirmed and suspected losses from malicious Google advertising between March 13 and March 30 alone, and warned that the true figure is likely higher.

There is no evidence that Hyperliquid's protocol was compromised. Instead, the attack appears to have targeted the user through an external phishing site before they reached the legitimate platform.