Key Takeaways
- An individual using Hyperliquid lost approximately $550,000 in USDC through a deceptive Google search advertisement
- DarcyAri from FlashRescue identified the theft by analyzing blockchain transaction records
- The stolen cryptocurrency was dispersed among three separate wallet addresses controlled by attackers
- Google deactivated the fraudulent advertiser’s account following notification
- Comparable phishing campaigns have also affected Trezor wallet users recently
On August 13, a cryptocurrency trader suffered losses totaling around $550,000 in USDC after interacting with a fraudulent phishing scheme disguised as a legitimate Google paid search listing.
DarcyAri, who co-founded the digital asset recovery platform FlashRescue, shared on-chain evidence revealing three separate fund transfers moving from the victim’s cryptocurrency wallet to addresses associated with the perpetrators.
The stolen assets were divided across three distinct transactions: one transfer of $27,500, another of $82,500, and a final movement of $440,020.
The malicious advertisement led the victim to a counterfeit website designed to mimic the authentic Hyperliquid platform, where sensitive information such as login credentials or wallet permissions were presumably harvested.
Google verified that the offending advertiser’s account has been terminated. A company representative stated that their systems prevent 99% of policy violations before ads go live and that more than 602 million fraudulent advertisements were eliminated in the previous year.
Growing Trend of Cryptocurrency Phishing via Paid Search
This incident represents just one example in a continuing series of phishing attacks leveraging Google’s advertising platform to target cryptocurrency users.
Earlier in April, cybersecurity organization SEAL reported blocking 356 harmful Google advertisement URLs during a multi-week period. Among those malicious links, several were specifically designed to imitate Hyperliquid.
SEAL observed that cybercriminals frequently exploit hijacked advertiser accounts to circumvent Google’s automated security screening processes.
The organization emphasized that fraudulent advertisements may remain active for mere minutes before successfully targeting a victim, complicating swift removal efforts.
This Hyperliquid case emerged shortly after another phishing operation aimed at Trezor customers. On August 7, Trezor released a public advisory regarding fake websites appearing as sponsored listings when users searched for “Trezor wallet.”
Trezor cautioned that submitting recovery seed phrases on these imposter sites would result in complete fund loss.
Additionally, in July, a different cryptocurrency holder lost $999,999 in USDT after authorizing a malicious token approval on the Ethereum network, as documented by Web3 security company Scam Sniffer.
Hyperliquid Platform Shows Continued Expansion
Importantly, there’s no evidence suggesting that the Hyperliquid protocol’s security was breached in this attack.
User engagement on the decentralized exchange has demonstrated consistent upward momentum. According to data from HyperTracker analytics, the platform recorded a peak of 263,666 active perpetual contract traders on August 6.
Active trader participation has climbed from approximately 150,000 in early January 2026, with accelerated expansion observed throughout the spring and summer months.
The platform’s native HYPE token delivered a 79.2% return during the latest quarter, achieving a record price of $76.90 on June 16 before finishing the period at $66.04.
The phishing incident had no observable impact on the protocol’s technical infrastructure or its sustained user base growth trajectory.
Cryptocurrency traders should refrain from clicking sponsored search listings when navigating to trading platforms and should always manually verify website URLs before connecting wallets or submitting any sensitive information.


