toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trade
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
Be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android version app
More download options

A Hyperliquid user loses $550000 to phishing

2026-08-14 08:50

A Hyperliquid user lost about $550,000 in USDC after clicking a paid Google search advertisement that redirected them to a phishing site designed to impersonate the decentralized trading platform, according to onchain transaction data shared by a crypto security specialist.

Darcy, co-founder of digital-asset tracing and recovery firm FlashRescue, said the stolen funds left the victim’s wallet through three separate onchain transfers to addresses identified as controlled by the attacker. The incident adds to evidence that paid search placements remain a profitable delivery channel for wallet-draining scams, even when the targeted protocol itself has not been compromised.

The apparent attack relied on a look-alike web domain rather than a vulnerability in Hyperliquid’s infrastructure. Such sites are built to resemble legitimate applications closely enough to persuade users to connect a wallet, sign a transaction, reveal credentials, or approve permissions that allow an attacker to move assets.

Paid ads continue to funnel users to counterfeit crypto sites

Malicious Google advertisements have repeatedly appeared above legitimate search results for cryptocurrency services, taking advantage of the tendency for users to treat prominent paid placements as trustworthy links. A fraudulent ad can direct a user through several redirects before landing on a counterfeit site, making the initial destination harder to identify from a search-results page alone.

The technique has been used against established protocols, wallet providers, trading platforms and token-creation tools. Attackers need only a small number of successful clicks to make the campaign worthwhile when a victim holds a large stablecoin balance or maintains broad wallet approvals.

In April, the Security Alliance, a crypto security nonprofit known as SEAL, said it had blocked 356 malicious Google ad URLs over several weeks. SEAL’s findings included pages impersonating Hyperliquid, alongside campaigns targeting Ethereum and Solana applications such as Jupiter, Raydium and Pump.fun.

SEAL said advertiser accounts associated with the URLs listed in its documentation were suspended. Its analysis also described how phishing operators use compromised or illicitly acquired advertising accounts to evade automated advertising checks, then rotate domains and campaigns after a takedown.

That short operational cycle complicates enforcement. SEAL reported that some malicious advertisements remain active for only minutes before reaching an initial victim, after which attackers can replace the ad, domain, or account. The system gives scammers a relatively cheap way to place fraudulent links in front of users already searching for a specific crypto service.

Google and Hyperliquid did not immediately respond to a request for comment cited in the supplied report.

Onchain transfers show the cost of a single mistake

The three transfers identified by FlashRescue illustrate how phishing losses can unfold rapidly once a wallet has been compromised or a harmful transaction has been approved. USDC transfers are visible on public blockchains, but traceability does not guarantee recovery, particularly if attackers quickly swap, bridge, or distribute the proceeds across multiple addresses.

Stablecoins are a frequent target because their dollar-denominated value is immediately clear and they can be moved without the price volatility associated with many crypto assets. In a phishing event, the attacker may seek direct token-transfer approval, access through a malicious wallet signature, or a transaction that changes spending permissions for an asset.

The reported $550,000 loss also shows why search-ad scams have remained persistent despite frequent warnings. A campaign does not need to deceive large numbers of people if one successful victim can yield hundreds of thousands of dollars. The economics encourage operators to continually test new domains, visual designs and keywords linked to popular protocols.

Scam Sniffer said users lost nearly $84 million to malicious links during 2025. The blockchain security platform’s data indicated that the number of people affected declined, while the amount stolen in successful incidents increased. That pattern is consistent with phishing operations focusing more heavily on wallets with larger balances or on applications where users routinely authorize high-value transactions.

Research cited in the supplied material from researcher de Vries put total digital-asset losses at about $1.3 billion by the middle of 2026. A single fake-support scam in January accounted for $284 million of that figure, according to the same research. The scale of individual cases can distort annual totals, but it also demonstrates how a convincing impersonation can lead to losses far beyond the value normally associated with retail phishing attempts.

Search habits are becoming part of wallet security

The most effective defense against search-ad impersonation is avoiding search results as a route to financial applications, particularly for transactions involving connected wallets. Entering a verified URL directly or using a previously saved bookmark reduces the chance of arriving at a sponsored counterfeit page.

Users can also verify the domain before connecting a wallet or approving any transaction. Minor changes in spelling, extra words, unusual country-code endings, and domains that imitate a project’s branding are common warning signs. A polished interface should not be treated as evidence that a site is legitimate; phishing kits can reproduce the appearance of major protocols with limited effort.

Separating crypto activity into a dedicated browser profile can further limit exposure to risky extensions, saved sessions, and incidental browsing. The approach does not prevent a user from approving a malicious transaction, but it can create a cleaner environment for checking domains and wallet prompts.

Wallet owners should also periodically review token approvals, which can permit smart contracts to spend assets without requiring a new approval each time. Revoking permissions that are no longer needed reduces the damage a previously approved malicious contract could cause. Hardware wallets add another barrier, though they cannot protect assets if their recovery phrase is entered into a phishing page or if the owner signs a transaction without understanding its effect.

Another related threat involves transaction-history poisoning. Attackers send small or zero-value transfers from addresses made to resemble legitimate contacts, hoping a user will later copy the fraudulent address from a wallet’s history. Checking the full recipient address, rather than relying on the first and last characters displayed by a wallet interface, remains essential before sending funds.

For Hyperliquid users and users of other high-value protocols, the reported theft is a reminder that the point of failure may sit outside the trading application itself: in the paid link selected before the wallet connection ever begins.


Avoid similar losses from fake ads—learn key protections in this phishing security guide before your next crypto transaction.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trade
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.