A Google ad scam allegedly cost a Hyperliquid user roughly $550,000 in USDC after the victim interacted with a phishing website promoted through a paid search result, according to security researcher and FlashRescue co-founder Darcy.
The incident, reportedly occurring on Aug. 13, involved approximately 550,019 USDC being transferred to three addresses that researchers identified as allegedly controlled by the attacker. While blockchain records confirm the movement of the funds, they do not independently prove that a Google advertisement was the mechanism used to deceive the victim.
The reported theft nevertheless adds to a growing pattern of malicious advertising campaigns targeting cryptocurrency users by impersonating well-known exchanges, wallets and decentralized applications.
Hyperliquid user loses 550,019 USDC in reported phishing attack
According to the transaction information cited by Darcy, the stolen funds were divided among three recipient addresses. Approximately 440,015 USDC went to one address, while another received about 82,503 USDC and a third received roughly 27,501 USDC.
The combined amount comes to approximately 550,019 USDC, closely matching the estimated $550,000 loss.
Darcy identified three wallet addresses allegedly associated with the attacker and attributed the incident to a paid Google advertisement impersonating Hyperliquid. GoPlus Security later flagged two of the same addresses in its own security warning.
The distinction between what is proven on-chain and what is attributed to the phishing campaign is important. Blockchain data can establish that assets moved between addresses, but it cannot reveal whether a victim clicked an advertisement, entered credentials into a fake website or approved a malicious transaction.
That makes the reported case another example of why attribution in crypto theft investigations often depends on combining transaction records with victim testimony, website infrastructure and security intelligence.
Google suspends advertiser as crypto ad threat grows
Google reportedly suspended the advertiser associated with the campaign after the incident was brought to its attention. The company has repeatedly said that combating scams is a major priority for its advertising systems.
Google’s 2025 Ads Safety Report provides some perspective on the scale of the challenge. The company said it blocked or removed more than 8.3 billion ads globally during 2025 and suspended 24.9 million advertiser accounts. Of those ads, 602 million were associated with scams, while four million advertiser accounts were suspended for scam-related activity.
Google also reported that its systems stopped more than 99% of policy-violating advertisements before they were served. Keerat Sharma, Google’s vice president and general manager of Ads Privacy and Safety, said the company’s Gemini-powered systems analyze hundreds of billions of signals, including account behavior and campaign patterns, to identify malicious activity.
Those defenses, however, have not eliminated the threat.
The latest Google ad scam allegation illustrates the challenge facing security teams: attackers can use legitimate-looking advertising infrastructure to place fraudulent destinations in front of users searching for trusted crypto platforms.
SEAL has tracked hundreds of malicious crypto ads
The Hyperliquid incident also fits into a broader campaign documented by the Security Alliance, or SEAL.
In an April 2026 report, SEAL said it had blocked more than 356 malicious advertising URLs targeting cryptocurrency applications and wallets. The organization said the campaigns had intensified in March and involved techniques such as cloaking and fingerprinting designed to evade automated advertising reviews and frustrate security researchers.
Hyperliquid was among the platforms targeted alongside major DeFi applications and crypto services. SEAL said attackers have repeatedly shifted between brands, with high-value protocols and trading platforms serving as particularly attractive targets.
The tactics can be particularly effective because sponsored search results may appear above legitimate organic results. A user searching for a familiar platform may therefore click what looks like the official destination without closely examining the URL.
SEAL has recommended that cryptocurrency users avoid relying on Google Search to access crypto applications and instead use verified bookmarks or trusted links.
That warning gives the Google ad scam problem a broader significance. The issue is not limited to one Hyperliquid account; it reflects a security weakness at the point where mainstream internet search intersects with high-value digital assets.
No evidence of a Hyperliquid protocol breach
Importantly, the available evidence does not indicate that Hyperliquid itself was hacked.
The reported loss appears to have occurred through an attack directed at the user, rather than through a compromise of Hyperliquid’s underlying trading infrastructure. Hyperliquid’s support documentation warns users to verify complete website URLs and says unauthorized transactions, missing funds or other unexpected wallet activity can indicate that a wallet has been compromised.
That distinction matters because a successful phishing attack can produce the same financial outcome as a technical exploit from the victim’s perspective while involving an entirely different security failure.
In this case, the Google ad scam allegation remains based on the reported victim account and security research rather than evidence contained within the blockchain transactions themselves.
The three recipient addresses, meanwhile, remain publicly traceable. Future movements could provide investigators with additional clues, particularly if the funds are transferred to a centralized exchange, bridge or other identifiable service.
As of Aug. 14, no publicly announced law-enforcement investigation or recovery effort tied specifically to this reported $550,000 loss had been identified in the sources reviewed.
For crypto users, the lesson is immediate: search rankings and sponsored placements are not proof of authenticity. A Google ad scam can exploit familiarity with a brand rather than a flaw in the blockchain itself.
With attackers continuing to target crypto applications through paid advertising, users are increasingly being urged to verify domains manually, bookmark official platforms and treat unexpected wallet prompts with extreme caution.
The reported Hyperliquid theft underscores the same point: in crypto, one wrong click can move hundreds of thousands of dollars in seconds, while recovering those funds can be far more difficult.