Hyperliquid User Loses $550K to Fake Google Ad Phishing Attack
A phishing attack on Hyperliquid users has resulted in significant financial losses for at least one user. On August 13, attackers bought Google Search advertisements using Hyperliquid-related keywords, which led to a fake website being displayed among the top search results. This website was designed to mimic the official Hyperliquid platform, and at least one user clicked on it, allowing the attackers to access their wallet.
The attackers then drained $550,000 from the user's account, transferring the funds to three blockchain addresses allegedly linked to them. According to Darcy Ari, co-founder of FlashRescue, this attack is a prime example of social engineering in action, where users are tricked into divulging sensitive information or authorizing malicious transactions.
Google has since suspended the campaign's associated advertiser, but this incident highlights the growing threat of search ad-based crypto phishing attacks. The Security Alliance (SEAL) has previously discovered over 356 malicious advertising URLs targeting cryptocurrency wallets and platforms.