A staggering loss was reported as a Hyperliquid platform user inadvertently surrendered around $550,000 in USDC after clicking on a fraudulent ad that appeared on Google search. The deceitful advertisement redirected the victim to a counterfeit site camouflaged as the official Hyperliquid webpage, resulting in the appropriation of their funds.
How did the funds get traced?
Darcy, a co-founder of FlashRescue, provided detailed insights into the case on August 13. He highlighted three suspect blockchain addresses believed to be associated with the culprit. Analyzing blockchain records, evidence showed transactions that funneled approximately 550,019 USDC to these identified addresses. The analysis noted transactions involving 440,015 USDC, 82,503 USDC, and 27,501 USDC.
The evidence underscored the path the USDC took into these wallets. However, it was primarily Darcy’s findings and the victim’s testimony that pieced together how the attacker executed the scam through a fake Google ad.
Google reacted swiftly by banning the advertiser behind the con, reiterating its “zero tolerance for scams” stance. It revealed that last year, it blocked or removed over 8.3 billion ads, out of which 602 million were linked to fraud attempts.
Can these scams be stopped?
It’s clear that despite Google’s efforts to prevent breaches, sophisticated scams persist. Security experts have identified a continuous stream of deceptive Google Ads targeting decentralized finance users, including those of Hyperliquid, running rampant for over a year. These fraudsters often rotate their tactics among prominent DeFi brands, making complete eradication of the ad campaigns a challenge.
Seal and other investigators identified that some fraudulent schemes utilize compromised verified Google advertiser accounts, which employ cloaking tactics. These involve legit-looking landing pages that trick automatic review systems but reveal malicious content to human users.
Growing concerns highlight that some scams rely on JavaScript embedded crypto drainers tricking victims into validating fraudulent transactions. While current data doesn’t directly connect a specific tool to the Hyperliquid case, it points out the constant threat posed by these deceptive tactics.
No indications exist that the Hyperliquid protocol itself was compromised; analysis shows the individual was scammed before accessing the legitimate platform.
- Rising threats of phishing scams require crypto users to employ extra vigilance.
- Google acknowledges continuous improvements in ad security but admits new scams frequently surface.
- Security analysts call for better integration tools like CryptoAppsy to streamline crucial trading activities and mitigate financial risks.
Hyperliquid patrons are reminded to exercise caution, ensuring platform access through trustworthy channels and steering clear of unreliable advertisements.



















English (US)