Newsroom
15 August, 2026 / News / AI / Tags: google, advertiser, hyperliquid, usdc, advertisements

A trader lost roughly 550,019 USDC on Aug. 13 after a sponsored search result led to a fake site mimicking the platform, security researchers reported
A user of the Hyperliquid trading platform suffered a loss of approximately $550,000 in USDC on Aug. 13 after clicking a sponsored Google search advertisement that directed them to a fraudulent website designed to resemble the official platform. FlashRescue co-founder Darcy reported the incident and identified three blockchain addresses that received the stolen funds.
On-chain records show the roughly 550,019 USDC was divided into three transfers of about 440,015 USDC, 82,503 USDC and 27,501 USDC. The recipient addresses were listed as 0x98b2761559A348968C994D9856dCfc96B6f13C55, 0x93b6B24DC6E6a1D5d72399e3A35498c4DbA1d6D1 and 0x6fE314fD4CF845f35fc461eD98e2FB8d9356B566. While the transfers confirm the movement of the assets, the connection to the Google advertisement relies on the researcher’s findings and information provided by the victim.
Google confirmed it had suspended the advertiser linked to the reported campaign. A company spokesperson stated that Google maintains zero tolerance for scams and that its systems prevented more than 99 percent of policy-violating advertisements from running during 2025. In its broader 2025 Ads Safety report, Google said it blocked or removed more than 8.3 billion ads and suspended 24.9 million advertiser accounts over the course of the year, including 602 million advertisements and four million accounts associated with scams.
These enforcement figures apply to Google’s global operations and are not specific to the Hyperliquid incident. Hyperliquid itself did not immediately provide a comment on the matter.
Security Alliance, known as SEAL, had previously documented a wider set of malicious advertising efforts targeting cryptocurrency platforms. In April, the group reported blocking more than 356 malicious advertising URLs over several weeks. Its data included 17 sites impersonating Hyperliquid, representing about 5 percent of the 352 entries in its brand breakdown.
SEAL described how attackers often rely on compromised or illicitly obtained verified advertiser accounts, combined with cloaking and fingerprinting techniques that help evade automated detection. Some campaigns present benign-looking Google-hosted pages to security systems while delivering malicious content to users through secondary frames. The organization advised users of cryptocurrency applications to avoid reaching platforms through Google Search results and instead rely on verified bookmarks.
Similar incidents have been reported previously. Fake Uniswap advertisements were linked to at least $400,000 in losses in May. SEAL separately calculated $1.27 million in confirmed and unattributed losses tied to suspected malicious Google advertisements between March 13 and March 30. In a more recent case, a Trezor user reported losses after interacting with a sponsored phishing result, prompting the hardware wallet firm to warn customers that sponsored search results can imitate official sites.
Available evidence indicates the Hyperliquid blockchain and trading protocol itself were not breached. The attack appears to have targeted the user through an external phishing site before any interaction with the legitimate platform occurred. Hyperliquid’s official support documentation already cautions users to verify complete website URLs, noting that scammers employ similar-looking domains. The guidance also states that unauthorized transactions, missing funds or unexpected multisig changes may signal a compromised wallet.
As of Aug. 14, no public announcement of a law-enforcement investigation or asset-recovery effort specific to this loss had been made. The three recipient addresses remain visible on-chain, and any future movement of the funds or identification of an exchange or bridge used by the attackers could provide additional avenues for investigation. For the present, the on-chain transfers support the reported loss figure, while the attribution to a Google advertisement rests on the account provided by the security researcher.









