Hyperliquid user loses $550,000 to Google ad phishing scam
Security & Exploits ·
A malicious Google search ad directed a Hyperliquid trader to a fake site that drained $550,000 in USDC from their account.
The user clicked what appeared to be a legitimate sponsored link in Google search results, only to land on a phishing page designed to mimic Hyperliquid's interface, according to theblock.co. The site tricked the victim into signing a transaction that transferred out $550,000 in USDC, a loss confirmed by a security specialist tracking the incident.
The attack fits a pattern flagged elsewhere in crypto security circles: fraudulent Google ads and fake security pages have become a growing vector for automated, AI-assisted phishing campaigns targeting crypto users, with one recent report noting malware hitting over 850 browser extensions. In this case, the ad's placement in Google's own search results gave it a veneer of legitimacy that helped bypass the skepticism users might apply to unsolicited links.
Security Alliance has responded by blocking 356 malicious ad URLs tied to the broader campaign, according to wublockchain.xyz, suggesting the Hyperliquid case was not an isolated incident but part of a wider phishing operation exploiting Google's ad platform to target derivatives traders specifically. The scale of the blocklist indicates attackers were running multiple parallel campaigns rather than a single spoofed listing.
Four distinct sources have corroborated the $550,000 loss figure and the Google ad vector, though details remain limited on how the phishing site was constructed, what specific wallet-draining technique was used, or whether Google has removed the offending advertisements. It is also not yet clear whether the victim has any path to recovering funds, or whether Hyperliquid itself has issued guidance to users about verifying official links following the incident. What remains to be seen is whether Security Alliance's blocklist effort curbs the broader campaign or whether additional victims surface as the 356 flagged URLs are investigated further.