Google ad phishing scam drains $550,000 from Hyperliquid user, security specialist says

A blockchain tracer said three transfers drained the user’s wallet after a paid ad sent them to a fake Hyperliquid site; Google says it suspended the advertiser.

Regulation•August 13, 2026, 2:45PM EDT
UPDATED: August 14, 2026, 1:02AM EDT
Google ad phishing scam drains $550,000 from Hyperliquid user, security specialist says

Quick Take

  • A Hyperliquid user appears to have lost roughly $550,000 in USDC after falling victim to a phishing scam promoted through a Google search ad, according to the co-founder of crypto firm FlashRescue.
  • In April, crypto security nonprofit SEAL said it had blocked 356 malicious Google ad URLs over a period of several weeks.
Advertisement

A Hyperliquid user appears to have lost roughly $550,000 in USDC after falling victim to a phishing scam promoted through a Google search ad, according to a crypto security specialist.

Darcy, co-founder of digital-asset tracing and recovery firm FlashRescue, posted blockchain data appearing to show three transfers from the user’s wallet to addresses he identified as controlled by the attacker. Darcy attributed the loss to a paid Google ad that directed the user to a website impersonating Hyperliquid.

Malicious search ads have long been used to target crypto users. The Block reported on the tactic as early as 2020, when scammers were buying ads that directed users searching for platforms such as Balancer and Uniswap to look-alike websites designed to steal private keys or obtain malicious wallet approvals.

Google told The Block that it had suspended the advertiser. “We have zero tolerance for scams and suspended this advertiser’s account,” a spokesperson said by email. “We block 99% of policy-violating ads before they ever run, and last year alone, we removed over 602 million scam ads.”

In April, crypto security nonprofit Security Alliance (SEAL) said it had blocked 356 malicious Google ad URLs over a period of several weeks, including several impersonating Hyperliquid. SEAL said Google had suspended all the advertiser accounts listed within its report.

Aside from Hyperliquid, scammers tend to target high total value locked protocols on Ethereum or Solana-native applications like Jupiter, Raydium and Pump.fun, SEAL added.

In its report, SEAL also said attackers sometimes use compromised or illicitly purchased advertiser accounts in order to evade Google’s automated reviews.

"Often, an ad is online for only minutes before finding its first victim. High-value losses motivate attackers to persist with deployments, regardless of the temporary sunk costs caused by SEAL's takedown efforts," the firm said.

Hyperliquid didn't immediately respond to a request for comment.