TLDR
- A Hyperliquid user lost roughly $550,000 in USDC after clicking a fake Google search ad
- FlashRescue co-founder DarcyAri flagged the attack using on-chain blockchain data
- Funds were split across three attacker wallet addresses
- Google suspended the advertiser’s account after being contacted
- Similar phishing ads have recently targeted Trezor hardware wallet users
A Hyperliquid user lost approximately $550,000 in USDC on August 13 after falling for a phishing scam run through a paid Google advertisement.
Hacker Uses Google Search Ad for Hyperliquid to Phish Users, Causing About $550,000 in Losses
According to DarcyAri, a hacker used a Google sponsored ad for “Hyperliquid” to lure users into a phishing site, resulting in a Google Search paid-ad phishing attack that has caused… pic.twitter.com/lbZnNmmuVy
— Wu Blockchain (@WuBlockchain) August 13, 2026
DarcyAri, co-founder of digital asset tracing firm FlashRescue, posted blockchain data showing three transfers from the victim’s wallet to addresses linked to the attacker.
The funds were split into three transactions: $27,500 to one address, $82,500 to a second, and $440,020 to a third.
The fake ad directed the user to a website impersonating Hyperliquid, where their credentials or wallet approvals were likely captured.
Google confirmed it suspended the advertiser’s account. A spokesperson said the company blocks 99% of policy-violating ads before they run and removed over 602 million scam ads last year.
A Pattern of Crypto Phishing Through Search Ads
This is not the first time phishing ads have targeted crypto users through Google search results.
In April, crypto security nonprofit SEAL said it blocked 356 malicious Google ad URLs over several weeks. Several of those URLs impersonated Hyperliquid specifically.
SEAL noted that attackers sometimes use compromised advertiser accounts to get past Google’s automated review systems.
The group warned that ads can be live for only minutes before finding a victim, making rapid takedowns difficult.
The Hyperliquid incident followed a separate campaign targeting Trezor users. On August 7, Trezor issued a warning about phishing websites appearing in sponsored Google results for the search term “Trezor wallet.”
Trezor warned that entering a wallet backup phrase on one of these sites could lead to total loss of funds.
In July, another crypto user lost $999,999 in USDT after signing a phishing token approval on Ethereum, according to Web3 security firm Scam Sniffer.
Hyperliquid’s Growth Continues
Despite the attack, there is no indication the Hyperliquid protocol itself was compromised.
Activity on the platform has been growing steadily. The number of active perpetual traders hit a new high of 263,666 on August 6, according to analytics platform HyperTracker.
Active trader counts have risen from around 150,000 in early January 2026, with growth picking up through spring and summer.
The HYPE token returned 79.2% in the most recent quarter, reaching an all-time high of $76.90 on June 16 before closing the quarter at $66.04.
The phishing attack did not appear to affect the protocol’s infrastructure or its ongoing user growth.
Crypto users are advised to avoid clicking sponsored search results when accessing trading platforms and to verify URLs directly before connecting wallets or entering any credentials.







