A Hyperliquid user lost roughly $550,000 in USDC on Aug. 13, 2026, after clicking a sponsored Google search ad that redirected them to a counterfeit version of the trading platform, according to FlashRescue co-founder Darcy.
Fake Hyperliquid Google ad linked to Inferno drainer steals USDC in an attack that appears to have relied on social engineering rather than a compromise of Hyperliquid’s underlying protocol.
Blockchain data showed three transfers totaling roughly 550,019 USDC, including approximately 440,015 USDC, 82,503 USDC and 27,501 USDC.
Fake Hyperliquid Google ad linked to Inferno drainer steals USDC in sophisticated phishing trap
The reported campaign was first highlighted by Darcy, co-founder of digital-asset tracing and recovery firm FlashRescue.
According to his investigation, attackers purchased Google search advertisements using Hyperliquid-related keywords, potentially placing the fraudulent listing prominently above legitimate results.
The Fake Hyperliquid Google ad linked to Inferno drainer steals USDC narrative is particularly alarming because the attack did not require hackers to breach Hyperliquid’s infrastructure.
Instead, criminals allegedly exploited the user’s trust in a familiar brand and a mainstream search engine.
The victim was reportedly redirected to a website designed to imitate Hyperliquid. Once the wallet interaction occurred, the attackers were able to obtain authorization that enabled the transfer of the victim’s USDC.
Available blockchain evidence confirms the movement of funds, although the precise sequence by which the victim was deceived relies on investigator findings and reported victim evidence.
Fake Hyperliquid Google ad linked to Inferno drainer steals USDC through automated infrastructure
Blockchain security firm Salus subsequently investigated the infrastructure behind the attack and said it had connections to the Inferno drainer ecosystem.
Salus described a professional drainer-as-a-service operation that allegedly provided phishing operators with ready-made tools for malicious scripts, approval commands, contract deployment, automated draining, cross-chain withdrawals, token swaps and fund consolidation.
The Fake Hyperliquid Google ad linked to Inferno drainer steals USDC case therefore illustrates how crypto theft has evolved beyond individually operated phishing schemes.
Criminal groups can increasingly outsource technical components while concentrating on acquiring victims through advertisements and convincing spoofed websites.
Salus also reported an automated revenue-sharing system. In the reported Hyperliquid incident, the phishing group allegedly handled the advertisement and fake website, while the backend infrastructure processed the stolen assets and distributed proceeds between designated addresses.
According to Salus, one address received 80% of the proceeds, another received 15%, and a third received 5%.
A separate address was identified as executing the drain. These findings, however, are investigator attributions rather than a judicial determination of who controlled the wallets.
Fake Hyperliquid Google ad linked to Inferno drainer steals USDC as Google faces scrutiny
The Fake Hyperliquid Google ad linked to Inferno drainer steals USDC incident also puts renewed pressure on the security of paid search advertising.
Google subsequently suspended the advertiser associated with the reported campaign, according to multiple reports.
Google has said it maintains “zero tolerance for scams” and reported that its systems blocked or removed more than 8.3 billion advertisements in 2025, including 602 million associated with scams.
Yet the incident demonstrates a painful weakness: even when advertising platforms deploy extensive automated defenses, sophisticated malicious campaigns can still reach users before detection.
Security researchers have warned that malicious crypto advertisements can be short-lived, sometimes appearing long enough to attract victims before being removed.
SEAL has previously identified hundreds of malicious advertising URLs targeting crypto wallets and platforms.
Why crypto users should worry
The Fake Hyperliquid Google ad linked to Inferno drainer steals USDC case highlights a broader shift in the crypto threat landscape.
Attackers no longer need to defeat sophisticated blockchain infrastructure if they can manipulate the human layer surrounding it.
For users, the warning is straightforward: sponsored search results should not automatically be treated as official links.
Crypto traders should verify domains independently, bookmark legitimate platforms and carefully inspect wallet approval requests before signing transactions.
The Fake Hyperliquid Google ad linked to Inferno drainer steals USDC attack ultimately shows how a single misleading click can turn a routine search into a six-figure loss.
As DeFi adoption grows, the battle against phishing may increasingly depend not only on smarter wallets and stronger blockchain security, but also on preventing malicious actors from purchasing credibility through mainstream advertising channels.
The Fake Hyperliquid Google ad linked to Inferno drainer steals USDC incident is a stark reminder that in crypto, the most dangerous attack may not always target the code—it may target the user’s trust.