- A Hyperliquid user reportedly lost about $550,000 in USDC.
- Darcy linked three transfers to a fake Hyperliquid site promoted through Google Ads.
- SEAL tracked more than 350 malicious crypto advertising URLs in 2026.
A Hyperliquid user reportedly lost about $550,000 in USDC after clicking a malicious Google search advertisement. FlashRescue co-founder Darcy linked the loss to a fake website impersonating Hyperliquid. Blockchain data showed three transfers from the user’s wallet to addresses identified as attacker-controlled. The reported Hyperliquid phishing attack did not involve a known exploit of Hyperliquid’s protocol.
Hyperliquid Phishing Attack Moves $550K Across Three Transfers
Darcy said the wallet sent three USDC transfers totalling roughly $550,000. He traced them to addresses linked to the suspected attacker. The Hyperliquid phishing attack reportedly started after a sponsored Google result redirected the user to the imitation site.
Blockchain records confirm transfers between wallet addresses. They cannot independently establish how an attacker obtained authorization.
The phishing attribution comes from Darcy’s investigation and the reported Google advertisement. Google and Hyperliquid had not responded when The Block published its report.
Malicious Google Ads Keep Targeting Crypto Trading Platforms
Security Alliance, or SEAL, documented more than 350 malicious Google advertising URLs during several weeks in 2026. Its research included pages impersonating Hyperliquid, Uniswap, Jupiter and Raydium. SEAL said attackers sometimes use compromised or purchased advertiser accounts to bypass automated reviews.
The group also found campaigns using cloaking and fingerprinting tools to evade detection. Some advertisements can reach victims within minutes. The Hyperliquid phishing attack fits a broader pattern of search ads directing crypto users toward cloned websites.
Fake pages can seek wallet approvals, login details or recovery phrases. SEAL said Google suspended advertiser accounts identified in its report. The group advises users to use verified bookmarks and check links before connecting wallets.
The reported Hyperliquid phishing attack follows other campaigns that target users before they reach legitimate crypto applications.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. CoinCryptoNewz is not responsible for any losses incurred. Readers should do their own research before making financial decisions.



