Hyperliquid Phishing Attack Drains $550K via Malicious Google Ad
A Hyperliquid user reportedly lost about $550,000 in USDC. Darcy linked three transfers to a fake Hyperliquid site promoted through Google Ads. SEAL tracked more than 350 malicious crypto adv
A
AnonymousCryptoCompass newsroom
August 13, 2026
2 min read
NEWS
CryptoCompass editorial visual for defi coverage.
A Hyperliquid user reportedly lost about $550,000 in USDC.
Darcy linked three transfers to a fake Hyperliquid site promoted through Google Ads.
SEAL tracked more than 350 malicious crypto advertising URLs in 2026.
A Hyperliquid user reportedly lost about $550,000 in USDC after clicking a malicious Google search advertisement. FlashRescue co-founder Darcy linked the loss to a fake website impersonating Hyperliquid. Blockchain data showed three transfers from the user’s wallet to addresses identified as attacker-controlled. The reported Hyperliquid phishing attack did not involve a known exploit of Hyperliquid’s protocol.
Hyperliquid Phishing Attack Moves $550K Across Three Transfers
Darcy said the wallet sent three USDC transfers totalling roughly $550,000. He traced them to addresses linked to the suspected attacker. The Hyperliquid phishing attack reportedly started after a sponsored Google result redirected the user to the imitation site.
Hyperliquid Google 付费广告钓鱼事件,造成资金损失 约550k攻击者地址:0x98b2761559A348968C994D9856dCfc96B6f13C550x93b6B24DC6E6a1D5d72399e3A35498c4DbA1d6D10x6fE314fD4CF845f35fc461eD98e2FB8d9356B566Google付费广告钓鱼事件频发,请注意保护资产安全 pic.twitter.com/9dVGLUNVJJ
Blockchain records confirm transfers between wallet addresses. They cannot independently establish how an attacker obtained authorization.
The phishing attribution comes from Darcy’s investigation and the reported Google advertisement. Google and Hyperliquid had not responded when The Block published its report.
Malicious Google Ads Keep Targeting Crypto Trading Platforms
Security Alliance, or SEAL, documented more than 350 malicious Google advertising URLs during several weeks in 2026. Its research included pages impersonating Hyperliquid, Uniswap, Jupiter and Raydium. SEAL said attackers sometimes use compromised or purchased advertiser accounts to bypass automated reviews.
The group also found campaigns using cloaking and fingerprinting tools to evade detection. Some advertisements can reach victims within minutes. The Hyperliquid phishing attack fits a broader pattern of search ads directing crypto users toward cloned websites.
Fake pages can seek wallet approvals, login details or recovery phrases. SEAL said Google suspended advertiser accounts identified in its report. The group advises users to use verified bookmarks and check links before connecting wallets.
The reported Hyperliquid phishing attack follows other campaigns that target users before they reach legitimate crypto applications.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. CoinCryptoNewz is not responsible for any losses incurred. Readers should do their own research before making financial decisions.
Balancer topluluğu, protokolün faaliyetlerini aşamalı olarak sonlandırmasını ve hazinedeki varlıkların BAL sahiplerine dağıtılmasını öngören kapsamlı bir teklif üzerinde karar verecek. Teklif
Could the next major crypto move already be forming before the crowd notices? The current market gives those questions plenty of fuel, with TRON, Cardano, Chainlink, and Hyperliquid showing v
Crypto markets are giving readers plenty to watch, with established networks continuing to compete for adoption, institutional attention, and ecosystem growth. XRP, Ethereum, Solana, Cardano,