Fake Hyperliquid Google Ad Drains $550K USDC via Phishing
A victim reportedly lost about $550,000 in USDC after clicking a fake Hyperliquid Google ad that led to an impersonation site. Danielle Walgenbach reports the incident was flagged on Aug. 13 by FlashRescue co-founder Darcy, who identified three attacker-linked addresses. Blockchain data showed roughly 550,019 USDC moving to those addresses (including transfers of ~440,015 USDC, 82,503 USDC, and 27,501 USDC). While the transfers confirm funds moved, they don’t independently prove the exact deception mechanism.
Google has suspended the advertiser tied to the campaign and said it has “zero tolerance for scams,” noting its systems prevented more than 99% of policy-violating ads from running in 2025. The article says Hyperliquid was already being impersonated in Google Ads, suggesting a sustained sponsored-search attack campaign against crypto users.
Security Alliance (SEAL) previously documented widespread malicious crypto advertising. It reported 356 malicious advertising URLs earlier this year, including 17 sites impersonating Hyperliquid, with tactics evolving over more than a year. Some campaigns used hacked/illegally obtained verified advertiser accounts plus cloaking to bypass automated checks. SEAL also observed browser-based JavaScript used to persuade victims to sign malicious transactions, but there is no public proof of which drainer tech—if any—was used in this latest fake Hyperliquid Google ad case.
No evidence suggests Hyperliquid’s protocol was compromised. The suspected vector is an external phishing site that users hit before reaching the legitimate platform.
Bearish
The incident is a clear DeFi-focused phishing scam using a fake Hyperliquid Google ad, which highlights ongoing exploitation risk for retail users. In the short term, such events typically increase caution around DeFi UX and wallet interaction safety, which can slightly dampen speculative appetite for related venues and reduce willingness to chase high-risk setups.
It also reinforces that external sponsored-search channels (not protocol code) are being abused. That can create a risk premium for traders who rely on timely entries and smooth on-chain interactions, especially if victims’ funds convert into major liquid assets (often via exchanges), potentially adding near-term sell pressure.
However, there is no evidence Hyperliquid’s protocol was compromised, so the broader market impact is likely limited and could fade if no additional large-scale drains emerge. Similar past cycles—when major brands were impersonated via search ads—usually caused localized sentiment hits and short-lived volatility rather than a sustained bearish trend across majors.