Users of the cryptocurrency trading platform Hyperliquid were lured to a phishing site through fake sponsored ads displayed in Google search results, resulting in the theft of approximately $550,000 (around 550,019 USDC) worth of assets.
According to a report published by Darcy, co-founder of security analysis firm FlashRescue, on August 13, 2026, the illicit fund transfers were executed across three blockchain addresses.
The breakdown of the transfers was analyzed to be approximately 441,015 USDC, 82,503 USDC, and 27,501 USDC. While the data on the blockchain clearly corroborates the transfer of funds, the assertion that the phishing ads were the direct trigger is based on tracking analysis by security researchers and reports from victims.
According to analysis by the security organization SEAL (Security Alliance), attackers are employing complex methods to evade legitimate security verification.
In addition to misusing compromised verified advertiser accounts, they have introduced cloaking technology that alters the displayed content based on the attributes of the visitors. A clever mechanism has been confirmed where safe Google-related pages are initially displayed, and malicious frames are called within them.
SEAL has been vigilant about threats impersonating the platform, noting that out of 356 confirmed dangerous ad URLs, 17 were related to Hyperliquid. Similar attacks have also been reported against other projects, with over $1.27 million (approximately 200 million yen) in damages recorded in just over half a month in late March. Past phishing incidents targeting users of Uniswap and Trezor have also been reported.
In response to reports, Google immediately suspended the accounts of the relevant advertisers. The company emphasizes its strict stance against fraudulent ads, reporting the removal of over 8.3 billion problematic ads and the suspension of more than 4 million accounts in the previous year.
In this incident, no traces of attacks on Hyperliquid's smart contracts or infrastructure have been confirmed. The core of the threat lies in users being directed to fake sites before reaching legitimate services.
To prevent damage, cryptocurrency users are strongly advised not to easily trust search engine ad spaces and to access through previously saved correct bookmarks. Additionally, they are urged to avoid signing suspicious transaction requests and to meticulously check the URL strings for any discrepancies.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.




















![[Coin Investment Indicator xRev ①] Definition of Revenue Multiple (xRev) and PUMP·AERO Cases](/public-static/10_5acc261b9b.png?format=avif)








