A user of the Hyperliquid cryptocurrency platform has reportedly lost approximately $550,000 in USDC after clicking on a malicious Google advertisement. The advertising link redirected the user to a fake website that imitated Hyperliquid’s official interface and was designed to deceive visitors.
According to preliminary information, the victim initially found Hyperliquid through Google search results and clicked on a sponsored listing. Instead of reaching the official platform, the user was directed to a phishing page that closely resembled the legitimate website.
Key Points
- A Hyperliquid user reportedly lost approximately $550,000 in USDC in a phishing attack.
- The victim allegedly reached the fraudulent website after clicking on a paid Google advertisement impersonating Hyperliquid.
- Blockchain analysis identified three USDC transfers from the victim’s wallet to addresses allegedly linked to the attacker.
- It remains unclear exactly how the attacker gained the ability to access and move the funds.
- The incident once again highlights the risks of using search advertisements to access cryptocurrency platforms.
The user reportedly lost a significant amount of USDC after interacting with a phishing website promoted on Google as a sponsored search result.
Darcy, co-founder of FlashRescue, a company specializing in tracking and recovering stolen digital assets, identified several transfers originating from the victim’s wallet. According to his findings, the funds were sent to three addresses that may be controlled by the suspected attacker.
According to Darcy, the user reached the fraudulent website after clicking on a sponsored Google result while searching for Hyperliquid.
The phishing website appears to have been designed to closely resemble the legitimate platform. This type of tactic is commonly used by scammers to prevent users from noticing anything suspicious until they connect their wallet or approve a transaction.
Blockchain Data Points to Three Suspicious Transfers
Blockchain data shared by Darcy indicates that the victim’s funds were withdrawn through three separate transactions. The USDC was sent to addresses that researchers have linked to the suspected attacker.
However, it remains unclear what specific action by the user enabled the attackers to gain access to the funds. Cryptocurrency phishing websites can rely on several different methods.
In some cases, users may be asked to connect their wallet to a fraudulent decentralized application. In others, they may be prompted to sign a transaction or grant a smart contract permission to use certain tokens. Attackers can also disguise malicious operations as ordinary actions within a familiar-looking interface.
The main problem is that phishing websites often closely replicate legitimate cryptocurrency platforms. They can use similar logos, colors, interface elements, wallet connection pages, and even familiar transaction flows.
As a result, users may fail to notice that they are dealing with a fake website and continue interacting with it as if it were the official platform.
Once funds have been transferred to a wallet controlled by an attacker, recovering them becomes extremely difficult. Most transactions on public blockchains are irreversible, meaning that an already confirmed transfer generally cannot be canceled through the blockchain itself.
Fraudulent Website Appeared Among Google’s Sponsored Results
According to available information, the phishing website appeared on Google as a sponsored result when the user searched for Hyperliquid.
Paid advertisements are displayed directly within search results and can sometimes appear above organic listings. This creates an additional risk because users may assume that the first link containing the name of the platform leads to its official website.
Scammers exploit this mechanism by purchasing search advertisements targeting keywords associated with well-known cryptocurrency brands. After clicking the advertisement, users are taken to a website with a similar name or domain that can look almost identical to the legitimate platform.
This type of attack has been used against cryptocurrency users for years.
As early as 2020, attackers were using Google advertising campaigns to impersonate popular DeFi platforms, including Balancer and Uniswap. Fake websites were created to trick users into revealing private keys or granting malicious smart contracts permission to control their assets.
Over time, the same strategy has been used against an increasing number of popular cryptocurrency projects. The reason is straightforward: DeFi users regularly connect wallets to different applications and sign transactions, meaning that a malicious request can appear completely normal.
Google Blocks Advertising Account After Attack Is Reported
After information about the fraudulent campaign was reported to Google, the company confirmed that it had blocked the advertising account associated with the phishing advertisement.
Google said it maintains a zero-tolerance policy toward fraudulent advertising. The company also stated that its systems automatically identify and block the vast majority of advertisements that violate its policies before they become available to users.
According to Google, the company removed more than 602 million fraudulent advertisements over the previous year.
Despite the scale of its automated security systems, attackers continue to search for ways to bypass detection mechanisms. Fraudulent advertising campaigns may remain active for only a short period, but even a few minutes can be enough to reach a user holding a large balance.
This makes such attacks particularly dangerous for the cryptocurrency industry. Unlike many traditional financial transactions, blockchain transfers often cannot be reversed once they have been confirmed.
Security Alliance Identifies Hundreds of Malicious Advertising URLs
The problem of phishing advertisements extends far beyond individual incidents.
The nonprofit Security Alliance, also known as SEAL, reported in April that it had blocked 356 malicious URLs associated with Google advertising campaigns over the course of several weeks.
Some of these advertisements were impersonating Hyperliquid. According to SEAL, Google subsequently blocked all advertising accounts identified by researchers in their report.
However, blocking individual accounts does not completely solve the problem.
Hyperliquid is just one of many cryptocurrency platforms targeted by these campaigns. Scammers also create copies of popular Ethereum protocols with high total value locked as well as applications within the Solana ecosystem.
Projects such as Jupiter, Raydium, and Pump.fun have also been targeted by similar attacks.
Popular DeFi applications are particularly attractive targets because their users regularly connect cryptocurrency wallets, swap assets, and approve transactions through smart contract interfaces.
As a result, a request to connect a wallet or sign a transaction may not immediately raise suspicion.
Scammers Use Stolen Advertising Accounts
SEAL has also highlighted another issue: attackers may gain access to existing advertising accounts that have already been approved and established.
These accounts can be stolen or acquired through illicit means. Using them may allow scammers to bypass some of Google’s automated verification procedures and launch new advertising campaigns more quickly.
Using an older, previously verified advertising account can make malicious activity more difficult to detect than campaigns launched from a completely new account.
Once an advertising account is blocked, attackers can move to another compromised profile. At the same time, they can change domains, create new advertisements, and launch additional campaigns.
As a result, combating this type of fraud becomes an ongoing process: after one set of advertisements is removed, new campaigns can emerge using different accounts and domains.
SEAL has noted that some fraudulent advertisements may remain active for only a few minutes. However, even such a short window can be enough for attackers to deceive at least one user.
The strategy remains attractive to criminals because of its potentially high profitability. If a single phishing campaign allows attackers to steal a large amount of money from one victim, the costs of creating new websites and advertising campaigns can quickly be recovered.
This creates an incentive to repeatedly launch similar attacks despite the efforts of search platforms and security researchers.
Cryptocurrency Users Should Carefully Check Website Addresses
The incident involving the Hyperliquid user once again demonstrates how dangerous it can be to access cryptocurrency services through sponsored search results.
The fact that a website appears on Google and is displayed in an advertising block does not mean that it belongs to the company or platform it claims to represent.
One of the most reliable ways to reduce the risk is to save the official website of a cryptocurrency platform in your browser bookmarks and access it directly instead of using search results.
Before connecting a wallet, users should carefully check the domain name. Even a small change in the website address, an additional character, or an unusual domain extension can indicate that the website is fraudulent.
Users should also carefully review every transaction before signing it. Particular attention should be paid to the permissions requested by a smart contract and the amounts specified in the transaction.
If an action on the website appears unusual or requests permissions that do not correspond to the intended operation, users should stop and verify the information before proceeding.
Hardware wallets and transaction simulation tools can provide an additional layer of protection. They may warn users about certain suspicious actions or unusual requests.
However, even these tools cannot provide absolute protection. If a user personally approves a malicious transaction or grants a smart contract a dangerous permission, security mechanisms may not always be able to prevent the resulting loss of funds.
For owners of large cryptocurrency portfolios, another useful security measure is to separate assets across different wallets.
Long-term holdings should ideally be stored separately from wallets that are regularly used to interact with DeFi applications, exchanges, and other decentralized services.
This approach can limit potential losses. Even if a user accidentally connects to a phishing website and signs a malicious transaction, the attacker may not automatically gain access to all of the user’s assets.
The case involving the loss of $550,000 in USDC demonstrates that even experienced cryptocurrency users need to exercise caution when interacting with search advertisements. Verifying the official domain, checking the source of the link, and carefully reviewing every transaction before signing remain among the key ways to protect digital assets.