Intelligence Brief
A Hyperliquid user appears to have transferred approximately 550,019 USDC to three attacker-linked addresses after interacting with an impersonation website promoted through a paid Google search result.
Darcy, co-founder of crypto recovery firm FlashRescue, attributed the compromise to a sponsored advertisement presented as a Hyperliquid result. Public blockchain data supports the reported transfers, but neither Google nor Hyperliquid had confirmed the complete attack path when the incident was reviewed.
???? Hyperliquid Google 付费广告钓鱼事件,造成资金损失 约550k
攻击者地址:
0x98b2761559A348968C994D9856dCfc96B6f13C550x93b6B24DC6E6a1D5d72399e3A35498c4DbA1d6D1
0x6fE314fD4CF845f35fc461eD98e2FB8d9356B566
Google付费广告钓鱼事件频发,请注意保护资产安全 pic.twitter.com/9dVGLUNVJJ
— Darcy 资产救援⛑️ (@DarcyAri) August 13, 2026
The available evidence does not indicate that Hyperliquid’s protocol was breached. The attack instead appears to have copied the platform’s identity and directed the user towards a malicious external site.
Security Alliance has tracked hundreds of malicious cryptocurrency advertising URLs, indicating that attackers continue to use conventional advertising systems to position fraudulent sites above legitimate search results.
Strategic Assessment
Search prominence can create false trust.
Users may treat a sponsored result carrying a familiar platform name as safer than an unsolicited message. Attackers benefit because the advertisement reaches people already intending to access the service. The victim arrives with both intent and an active wallet.
Hyperliquid bears reputational exposure despite no confirmed protocol compromise. Google faces questions about advertiser screening and response time. The user carries the financial loss because blockchain transactions generally cannot be reversed once signed and settled.
The exact compromise mechanism remains uncertain. The transfers are visible; the alleged advertisement journey depends on the investigator’s account. That distinction should remain explicit unless Google, Hyperliquid or the victim publishes further evidence.
Blocking one domain will not close the threat. Attackers can rotate URLs, accounts and advertising copy faster than static warning lists are updated.