VERSE PRESS

Crypto News, Global First.

Google Search Ad Scam Costs Hyperliquid User $550,000 in USDC

A fraudulent Google-sponsored search result impersonating Hyperliquid drained roughly $550,000 in USDC from a single user on August 13, 2026, in the latest of a series of organized phishing campaigns exploiting crypto users through paid search advertising.

|

DarcyAri, co-founder of blockchain recovery service FlashRescue, flagged the theft on X on Thursday, tracing stolen funds to three separate attacker-controlled wallets. On-chain records show the bulk of the funds, $440,020 USDC, landed in one address (0x98b2...C55), with the remainder split between two others receiving $82,503 and $27,501. The primary transaction hash is 0xd0920a30a4f2e554e9d3a73dbcc12e8fc825dd874f23bc79f2a476408a7a11b0. Hyperliquid's own protocol was not compromised. The attacker's entry point was a cloned website served through Google's ad auction, not a breach of the trading platform itself.

The Hyperliquid team had not issued a public statement as of publication time. The platform itself remains one of the dominant forces in decentralized derivatives trading, with roughly $7.3 billion in open interest, a 24-hour trading volume near $3.5 billion, and a HYPE token price of approximately $57.30 (CoinMarketCap rank: 9). That scale makes Hyperliquid a high-value impersonation target. According to data from crypto security nonprofit Security Alliance (SEAL), Hyperliquid accounts for about 5% of the 356 malicious Google ad URLs the group has tracked and reported for removal.

A Sustained, Organized Operation

This incident is not isolated. Crypto users searching for "Hyperliquid" in Google encountered a sponsored result at the top of the page linking to a pixel-perfect clone of the real trading interface. SEAL's technical analysis of these campaigns found a consistent three-part structure: a lightweight decoy page hosted on Arweave's decentralized storage, a highly convincing front-end replica served through Cloudflare Workers, and obfuscated wallet-drainer scripts that route Ethereum calls through an attacker-controlled proxy. That proxy gives attackers real-time visibility into what a victim holds, allowing attackers to tailor their malicious payload to a victim's specific holdings.

SEAL has noted that "an ad is online for only minutes before finding its first victim."

To avoid detection, the campaigns use fingerprinting tools to redirect security researchers to harmless pages like Wikipedia, while genuine targets see the phishing site. Many campaigns run through hijacked legitimate Google advertiser accounts, some purchased on criminal forums. On March 29, 2026, a compromised Apple Inc. advertiser account was used to serve crypto phishing ads. Google has suspended identified accounts when notified, but attackers can relaunch new campaigns within minutes using fresh or stolen credentials. In the March 13 to 30, 2026 period alone, SEAL confirmed $810,929 in directly stolen funds linked to this campaign structure, with total estimated losses for that window reaching $1,274,259.

The theft follows a similar Google-ad phishing campaign targeting Trezor users on August 7, just six days earlier, which drained around 24 BTC (approximately $1.6 million) from at least 80 reported victims. While both attacks exploited Google-sponsored search results as the delivery mechanism, the approaches differed materially: the Trezor campaign relied on seed-phrase harvesting, while the Hyperliquid attack used drainer scripts requiring only a wallet approval signature.

Uniswap founder Hayden Adams has argued, as reported by Memeburn, that Google's advertising model is a systemic threat to crypto users and that the platform profits from the same ads that drain wallets.

Two Drainer-as-a-Service (DaaS) platforms, Inferno Drainer and Vanilla Drainer, power much of this activity as commercial tools rented to attackers on a revenue-sharing basis. Operators take a 20% cut of whatever is stolen. Critically, these services require no access to private keys. A single wallet approval signature from the victim is enough to empty an account.

Regional Users Face Elevated Risk

For users in South Asia and Africa, the risk profile is sharper than it may appear in Western crypto discourse. Google Search is the dominant entry point to the web in India and Pakistan, with limited competition from alternative search engines, and African crypto users disproportionately rely on mobile-first Google Search to reach DeFi platforms rather than bookmarked URLs. SEAL's analysis has identified South Asian and Gulf region users among the active targeting zones for these campaigns, a finding that connects the search-navigation habit directly to documented attacker intent.

Nigeria recorded 1.6 million online cyberattack attempts in the first half of 2026 alone, according to BusinessDay Nigeria. Separately, 18.4% of Nigerian internet users encountered web-based threats during that period, according to Nigeria Communications Week citing Kaspersky data.

Kenya's web threat exposure rate reached 21.2%, the second-highest globally in one tracking study, according to CybersecurityNews citing Kaspersky data.

Both countries are among Africa's largest crypto adoption markets, and both have seen rapid growth in stablecoin usage, precisely the asset class stolen in this attack.

Regulatory frameworks in these regions have yet to address the specific threat of DeFi phishing via search advertising. India's SEBI and Nigeria's SEC have focused primarily on exchange licensing, leaving the user-protection gap at the search-results layer unaddressed by policy.

What Users Can Do Now

Security researchers offer consistent advice: bookmark official URLs directly and never navigate to DeFi platforms through search results, sponsored or otherwise. For Hyperliquid specifically, users should confirm the correct trading URL directly from the platform's verified official channels before bookmarking it. SEAL recommends using DefiLlama's URL verification tool (search.defillama.com) to confirm a protocol address before connecting a wallet. Installing an ad blocker such as uBlock Origin or using the Brave browser removes sponsored results from view entirely. Users should also regularly revoke unused token approvals through tools like revoke.cash.

With Q1 2026 phishing losses already at $290 million industry-wide, and total 2025 crypto fraud reaching $11.36 billion, a 22% increase over the prior year, the incentive structure for these campaigns is unlikely to change without pressure on Google to implement stronger verification requirements for financial services advertisers. Until that happens, the search bar remains one of crypto's most dangerous attack surfaces.