Key Takeaways
- Cryptocurrency trader lost approximately $550,000 in USDC through malicious Google search advertisement
- DarcyAri from FlashRescue identified the fraudulent transaction through blockchain analysis
- Stolen assets were distributed to three separate attacker-controlled wallets
- Google took action by suspending the fraudulent advertiser’s account
- Recent wave of phishing campaigns has also targeted users of Trezor wallets
On August 13, a cryptocurrency trader using Hyperliquid became the victim of an elaborate phishing operation, losing around $550,000 in USDC after interacting with a fraudulent paid advertisement on Google.
DarcyAri, who co-founded the digital asset recovery platform FlashRescue, identified the fraudulent activity by analyzing on-chain transaction records that revealed three separate transfers originating from the victim’s cryptocurrency wallet to addresses controlled by the scammer.
The stolen cryptocurrency was dispersed across three distinct transactions: an initial transfer of $27,500, followed by $82,500 to another address, and finally $440,020 to a third wallet.
The malicious advertisement redirected the unsuspecting user to a counterfeit website designed to mimic Hyperliquid’s legitimate platform, where attackers harvested login credentials or obtained unauthorized wallet permissions.
Google acknowledged the incident and deactivated the fraudulent advertiser’s account. A company representative stated that their systems prevent 99% of policy-violating advertisements from appearing and that they eliminated more than 602 million fraudulent ads throughout the previous year.
Escalating Trend of Cryptocurrency Phishing via Paid Search Results
This incident represents just one example in a growing pattern of phishing attacks exploiting Google’s advertising platform to target cryptocurrency users.
Earlier this year in April, cryptocurrency security organization SEAL reported successfully intercepting 356 malicious Google advertisement URLs during a multi-week period. Among these fraudulent links, several specifically impersonated the Hyperliquid platform.
SEAL discovered that threat actors frequently exploit hijacked advertiser accounts to circumvent Google’s automated security screening processes.
The organization emphasized that fraudulent advertisements may remain active for mere minutes before successfully deceiving a victim, creating significant challenges for timely intervention and removal.
Prior to the Hyperliquid attack, scammers launched a coordinated operation against Trezor hardware wallet users. On August 7, Trezor published an urgent security alert regarding fraudulent websites appearing as sponsored listings in Google search results when users searched for “Trezor wallet.”
Trezor cautioned that providing seed phrase information on these deceptive platforms could result in complete and irreversible loss of cryptocurrency holdings.
In a separate incident from July, another cryptocurrency holder was defrauded of $999,999 in USDT after authorizing a malicious token approval transaction on the Ethereum blockchain, as documented by Web3 security company Scam Sniffer.
Platform Metrics Show Continued Expansion
The phishing incident appears to be an isolated case of user deception rather than a vulnerability in Hyperliquid’s underlying protocol or security infrastructure.
User engagement on the decentralized exchange has demonstrated consistent upward momentum. According to data from analytics service HyperTracker, the platform recorded a record-breaking 263,666 active perpetual futures traders on August 6.
Active trader participation has experienced substantial growth from approximately 150,000 users in early January 2026, with acceleration continuing throughout the spring and summer months.
The platform’s native HYPE token delivered impressive returns of 79.2% during the most recent quarter, peaking at an all-time high valuation of $76.90 on June 16 before settling at $66.04 by quarter’s end.
The phishing attack had no observable impact on the protocol’s technical operations or its trajectory of expanding user adoption.
Security experts recommend that cryptocurrency users exercise caution by avoiding sponsored search results when navigating to trading platforms, and to independently verify website addresses before authorizing wallet connections or submitting sensitive authentication information.





