Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Hyperliquid trader loses $550K to phishing scam via malicious Google ad
00

Hyperliquid trader loses $550K to phishing scam via malicious Google ad

Aug 13, 2026

A Hyperliquid user loses approximately $550,000 in USDC on August 13, 2026, after interacting with a phishing website promoted via a fraudulent Google search advertisement. The stolen funds are split among three attacker-controlled addresses. While Hyperliquid's underlying protocol remains secure, Google suspends the malicious advertiser account. The incident highlights a growing trend of search-ad phishing campaigns targeting crypto users, similar to recent attacks targeting Trezor wallet holders.

Hyperliquid phishing via Google

  • ▪The phishing incident did not involve any security breach of the Hyperliquid protocol, blockchain, or trading infrastructure.
  • ▪A Hyperliquid user lost approximately $550,000 in USDC on August 13, 2026, after interacting with a phishing website promoted through a fraudulent Google search advertisement.

USDC theft distribution

  • ▪The three recipient addresses linked to the Hyperliquid phishing incident are 0x98b2761559A348968C994D9856dCfc96B6f13C55, 0x93b6B24DC6E6a1D5d72399e3A35498c4DbA1d6D1, and 0x6fE314fD4CF845f35fc461eD98e2FB8d9356B566.
  • ▪The stolen USDC was split among three attacker-controlled addresses, with approximately 440,015 USDC, 82,503 USDC, and 27,501 USDC sent to the respective wallets.

Google advertiser suspension

  • ▪Google's 2025 Ads Safety report states that the company blocked or removed over 8.3 billion ads and suspended 24.9 million advertiser accounts globally, including 602 million scam ads.
  • ▪Google suspended the advertiser account connected to the fraudulent Hyperliquid campaign following reports of the phishing incident.

SEAL malicious URL blocking

  • ▪The Security Alliance (SEAL) blocked more than 356 malicious advertising URLs during a campaign in April 2026, which included 17 Hyperliquid impersonation sites.
  • ▪According to the Security Alliance (SEAL), attackers bypass Google's automated verification checks by using hijacked or illicitly purchased verified advertiser accounts alongside cloaking and fingerprinting.

Crypto phishing attack pattern

  • ▪On August 7, 2026, Trezor issued a warning regarding sponsored Google search results that directed users to phishing websites impersonating the Trezor wallet brand.
  • ▪In July 2026, a cryptocurrency user lost $999,999 in USDT after signing a malicious token approval on Ethereum, as reported by Web3 security firm Scam Sniffer.

3 sources

Cryptotimes
Hyperliquid Users Lose $550K in Alleged Phishing Attack Via Google Ads
View source article
Blockonomi
Hyperliquid Trader Loses $550K to Malicious Google Ad Campaign - Blockonomi
View source article
Crypto
Hyperliquid user reportedly loses $550K in Google ad scam
View source article

Story comments

Loading comments…

Related Projects

UsdcGoogleHyperliquid

Topics

Crypto securityDeFiPhishing attacksStablecoinsCrypto fraud