Trader loses $550,000 to Google ad scam impersonating Hyperliquid

2 hours ago 8

A crypto trader lost approximately $550,000 in USDC after clicking on a fraudulent Google ad that impersonated Hyperliquid, the popular decentralized perpetual futures exchange. The phishing site, designed to look identical to the real platform, drained the victim’s wallet in what security researchers are calling yet another example of search engine advertising being weaponized against DeFi users.

The attack didn’t exploit any vulnerability in Hyperliquid’s smart contracts or on-chain infrastructure. It exploited something far simpler: human trust in Google search results.

How the scam worked

The attacker purchased a sponsored ad on Google that appeared when users searched for Hyperliquid. Sponsored results sit above organic search results, which means the fraudulent link was likely the first thing the victim saw. Clicking it redirected to a convincing replica of Hyperliquid’s interface, where the phishing site was engineered to steal wallet approvals or seed phrases.

Security researcher Darcy, co-founder of FlashRescue, flagged the incident and noted that the stolen funds, totaling roughly 550,019 USDC, were subsequently moved to three separate wallet addresses controlled by the attackers.

Google confirmed it suspended the advertiser behind the fraudulent ad.

Hyperliquid’s on-chain systems were never compromised. The platform’s smart contracts, order matching engine, and backend infrastructure all functioned normally throughout. This was purely a front-end impersonation attack.

A recurring pattern in crypto phishing

Hyperliquid is a particularly attractive target for this kind of attack. The platform operates as a high-performance Layer-1 blockchain dedicated to decentralized perpetual futures and spot trading, supporting hundreds of markets with leverage up to 40x. It uses USDC as its primary margin and quote asset, and its native token HYPE serves governance and staking functions. The combination of high-leverage trading and substantial capital flows means that active Hyperliquid users often have large USDC balances connected to their wallets, making them lucrative targets.

What traders should watch for

For individual traders, the defensive measures are straightforward but require discipline. Always verify URLs before connecting a wallet, particularly when arriving at a site through a search engine. Bookmark the official domains of platforms you use regularly and navigate to them directly rather than through Google. Be especially cautious of any site that asks you to re-enter a seed phrase or approve an unusually broad token spending permission.

Hardware wallets add an extra layer of protection by requiring physical confirmation of transactions, which gives users a moment to review what they’re actually signing.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article