Hyperliquid Phishing Attack Drains $550K via Malicious Google Ad
A Hyperliquid user reportedly lost about $550,000 in USDC. Darcy linked three transfers to a fake Hyperliquid site promoted through Google Ads. SEAL tracked more than 350 malicious crypto adv
A
AnonymousCryptoCompass newsroom
August 13, 2026
2 min read
NEWS
CryptoCompass editorial visual for defi coverage.
A Hyperliquid user reportedly lost about $550,000 in USDC.
Darcy linked three transfers to a fake Hyperliquid site promoted through Google Ads.
SEAL tracked more than 350 malicious crypto advertising URLs in 2026.
A Hyperliquid user reportedly lost about $550,000 in USDC after clicking a malicious Google search advertisement. FlashRescue co-founder Darcy linked the loss to a fake website impersonating Hyperliquid. Blockchain data showed three transfers from the user’s wallet to addresses identified as attacker-controlled. The reported Hyperliquid phishing attack did not involve a known exploit of Hyperliquid’s protocol.
Hyperliquid Phishing Attack Moves $550K Across Three Transfers
Darcy said the wallet sent three USDC transfers totalling roughly $550,000. He traced them to addresses linked to the suspected attacker. The Hyperliquid phishing attack reportedly started after a sponsored Google result redirected the user to the imitation site.
Hyperliquid Google 付费广告钓鱼事件,造成资金损失 约550k攻击者地址:0x98b2761559A348968C994D9856dCfc96B6f13C550x93b6B24DC6E6a1D5d72399e3A35498c4DbA1d6D10x6fE314fD4CF845f35fc461eD98e2FB8d9356B566Google付费广告钓鱼事件频发,请注意保护资产安全 pic.twitter.com/9dVGLUNVJJ
Blockchain records confirm transfers between wallet addresses. They cannot independently establish how an attacker obtained authorization.
The phishing attribution comes from Darcy’s investigation and the reported Google advertisement. Google and Hyperliquid had not responded when The Block published its report.
Malicious Google Ads Keep Targeting Crypto Trading Platforms
Security Alliance, or SEAL, documented more than 350 malicious Google advertising URLs during several weeks in 2026. Its research included pages impersonating Hyperliquid, Uniswap, Jupiter and Raydium. SEAL said attackers sometimes use compromised or purchased advertiser accounts to bypass automated reviews.
The group also found campaigns using cloaking and fingerprinting tools to evade detection. Some advertisements can reach victims within minutes. The Hyperliquid phishing attack fits a broader pattern of search ads directing crypto users toward cloned websites.
Fake pages can seek wallet approvals, login details or recovery phrases. SEAL said Google suspended advertiser accounts identified in its report. The group advises users to use verified bookmarks and check links before connecting wallets.
The reported Hyperliquid phishing attack follows other campaigns that target users before they reach legitimate crypto applications.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. CoinCryptoNewz is not responsible for any losses incurred. Readers should do their own research before making financial decisions.
Crypto commentator Digital Asset Investor (@digitalassetbuy) recently shared a video clip featuring Ripple CEO Brad Garlinghouse. The clip addressed a pointed question about what happens to X
A cybersecurity firm has reported a crypto phishing campaign that targeted a pool of 885,000 phone numbers, according to reporting on the disclosure. The figure describes the scale of the out
Grayscale Research says the SEC's Regulation Crypto Assets proposal could clarify U.S. rules for token-based fundraising. The proposed framework targets newly issued tokens, with eligible iss