A user of the Hyperliquid trading platform lost approximately $550,000 in USDC after inadvertently clicking on a malicious advertisement displayed via Google search. The ad redirected the user to a fraudulent website designed to mimic the official Hyperliquid site, leading to the theft of their funds.
Funds traced to attacker-controlled addresses
Darcy, co-founder of FlashRescue, detailed the incident on August 13, highlighting three blockchain addresses suspected to belong to the perpetrator. Blockchain records revealed separate transfers totaling about 550,019 USDC being sent to these addresses. Notable movements included transactions of 440,015 USDC, 82,503 USDC, and 27,501 USDC.
These transfers clearly confirm that the lost USDC ended up in the identified wallets. However, only Darcy’s findings and evidence provided by the victim established the specific route by which the attacker exploited the individual, namely through a deceptive Google advertisement.
Google responded aggressively by suspending the advertiser responsible for the scam, emphasizing its “zero tolerance for scams” and revealing that its systems blocked or removed more than 8.3 billion ads last year. This figure included 602 million advertisements directly tied to fraudulent activities.
For 2025, Google stated its automated controls prevented over 99% of policy-violating ads from going live. The search giant reiterated its commitment to safeguarding users against phishing and fraud schemes, but acknowledged that sophisticated scams still emerge despite ongoing efforts.
Persistent phishing using Google Ads
Security organizations have observed that malicious Google Ads targeting DeFi users like those of Hyperliquid have been circulating consistently for more than a year. Attackers frequently rotate through major decentralized finance brands, making it difficult to shut down these campaigns entirely.
According to SEAL, some of these operations employ compromised or illicitly acquired verified Google advertiser accounts. They often pair these accounts with cloaking techniques where initial landing pages—sometimes even hosted by Google—appear legitimate to automated review systems. Once a human user accesses the site, deceptive content is loaded through additional frames.
Investigators also noted the growing use of crypto drainers that rely on JavaScript embedded in browsers, tricking victims into approving malicious transactions. However, current evidence does not link a particular drainer tool to the latest Hyperliquid case.
There is no indication that the Hyperliquid protocol suffered any breach; the user was deceived before ever interacting with the legitimate trading platform, according to initial analyses.
Given the rapid pace of such attacks, market participants increasingly recognize the risk of fragmented tools and information sources. In a market where a single Fed decision or a sudden altcoin listing can change everything in seconds, jumping between different apps for charts, news, and portfolio tracking is costing investors money. Smart traders are now utilizing privacy-first tools like CryptoAppsy to consolidate everything. Without even the hassle of creating an account, you get real-time charts, smart price alerts, coin-specific news, and critical macro data all on one screen.
As of now, Hyperliquid users are urged to remain cautious and to only access the platform directly through trusted links, avoiding all third-party advertisements.





USDT
AAPL
