A Hyperliquid user lost about $550,000 in USDC after clicking a paid Google search advertisement that redirected them to a phishing site designed to impersonate the decentralized trading platform, according to onchain transaction data shared by a crypto security specialist.
Darcy, co-founder of digital-asset tracing and recovery firm FlashRescue, said the stolen funds left the victim’s wallet through three separate onchain transfers to addresses identified as controlled by the attacker. The incident adds to evidence that paid search placements remain a profitable delivery channel for wallet-draining scams, even when the targeted protocol itself has not been compromised.
The apparent attack relied on a look-alike web domain rather than a vulnerability in Hyperliquid’s infrastructure. Such sites are built to resemble legitimate applications closely enough to persuade users to connect a wallet, sign a transaction, reveal credentials, or approve permissions that allow an attacker to move assets.
Paid ads continue to funnel users to counterfeit crypto sites
Malicious Google advertisements have repeatedly appeared above legitimate search results for cryptocurrency services, taking advantage of the tendency for users to treat prominent paid placements as trustworthy links. A fraudulent ad can direct a user through several redirects before landing on a counterfeit site, making the initial destination harder to identify from a search-results page alone.
The technique has been used against established protocols, wallet providers, trading platforms and token-creation tools. Attackers need only a small number of successful clicks to make the campaign worthwhile when a victim holds a large stablecoin balance or maintains broad wallet approvals.
In April, the Security Alliance, a crypto security nonprofit known as SEAL, said it had blocked 356 malicious Google ad URLs over several weeks. SEAL’s findings included pages impersonating Hyperliquid, alongside campaigns targeting Ethereum and Solana applications such as Jupiter, Raydium and Pump.fun.
SEAL said advertiser accounts associated with the URLs listed in its documentation were suspended. Its analysis also described how phishing operators use compromised or illicitly acquired advertising accounts to evade automated advertising checks, then rotate domains and campaigns after a takedown.
That short operational cycle complicates enforcement. SEAL reported that some malicious advertisements remain active for only minutes before reaching an initial victim, after which attackers can replace the ad, domain, or account. The system gives scammers a relatively cheap way to place fraudulent links in front of users already searching for a specific crypto service.
Google and Hyperliquid did not immediately respond to a request for comment cited in the supplied report.
Onchain transfers show the cost of a single mistake
The three transfers identified by FlashRescue illustrate how phishing losses can unfold rapidly once a wallet has been compromised or a harmful transaction has been approved. USDC transfers are visible on public blockchains, but traceability does not guarantee recovery, particularly if attackers quickly swap, bridge, or distribute the proceeds across multiple addresses.
Stablecoins are a frequent target because their dollar-denominated value is immediately clear and they can be moved without the price volatility associated with many crypto assets. In a phishing event, the attacker may seek direct token-transfer approval, access through a malicious wallet signature, or a transaction that changes spending permissions for an asset.
The reported $550,000 loss also shows why search-ad scams have remained persistent despite frequent warnings. A campaign does not need to deceive large numbers of people if one successful victim can yield hundreds of thousands of dollars. The economics encourage operators to continually test new domains, visual designs and keywords linked to popular protocols.
Scam Sniffer said users lost nearly $84 million to malicious links during 2025. The blockchain security platform’s data indicated that the number of people affected declined, while the amount stolen in successful incidents increased. That pattern is consistent with phishing operations focusing more heavily on wallets with larger balances or on applications where users routinely authorize high-value transactions.
Research cited in the supplied material from researcher de Vries put total digital-asset losses at about $1.3 billion by the middle of 2026. A single fake-support scam in January accounted for $284 million of that figure, according to the same research. The scale of individual cases can distort annual totals, but it also demonstrates how a convincing impersonation can lead to losses far beyond the value normally associated with retail phishing attempts.
Search habits are becoming part of wallet security
The most effective defense against search-ad impersonation is avoiding search results as a route to financial applications, particularly for transactions involving connected wallets. Entering a verified URL directly or using a previously saved bookmark reduces the chance of arriving at a sponsored counterfeit page.
Users can also verify the domain before connecting a wallet or approving any transaction. Minor changes in spelling, extra words, unusual country-code endings, and domains that imitate a project’s branding are common warning signs. A polished interface should not be treated as evidence that a site is legitimate; phishing kits can reproduce the appearance of major protocols with limited effort.
Separating crypto activity into a dedicated browser profile can further limit exposure to risky extensions, saved sessions, and incidental browsing. The approach does not prevent a user from approving a malicious transaction, but it can create a cleaner environment for checking domains and wallet prompts.
Wallet owners should also periodically review token approvals, which can permit smart contracts to spend assets without requiring a new approval each time. Revoking permissions that are no longer needed reduces the damage a previously approved malicious contract could cause. Hardware wallets add another barrier, though they cannot protect assets if their recovery phrase is entered into a phishing page or if the owner signs a transaction without understanding its effect.
Another related threat involves transaction-history poisoning. Attackers send small or zero-value transfers from addresses made to resemble legitimate contacts, hoping a user will later copy the fraudulent address from a wallet’s history. Checking the full recipient address, rather than relying on the first and last characters displayed by a wallet interface, remains essential before sending funds.
For Hyperliquid users and users of other high-value protocols, the reported theft is a reminder that the point of failure may sit outside the trading application itself: in the paid link selected before the wallet connection ever begins.
Avoid similar losses from fake ads—learn key protections in this phishing security guide before your next crypto transaction.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
