$550,000 Lost as Malicious Ad Targets Hyperliquid Users
A malicious Google ad targeting Hyperliquid users has resulted in a loss of approximately $550,000. Darcy, co-founder of FlashRescue, flagged the incident on August 13 and attributed it to a paid advertisement appearing in search results for Hyperliquid.
The ad directed the user to a website impersonating the decentralized trading platform, which then imitated the genuine interface to obtain wallet credentials or authorization for asset transfer. Blockchain data showed funds moving from the affected wallet to three addresses identified as belonging to the attacker, totaling about 550,019 USDC in transfers.
The incident is not isolated, with Security Alliance identifying and blocking 356 malicious Google advertising URLs in April, including several impersonating Hyperliquid. The economics behind such attacks are straightforward: valuable crypto accounts make the advertising expense worthwhile if even a small number of users are deceived.