Particle.news
Download on the App Store

Trader Loses $550,000 After Phishing Site Appeared in Google Paid Search

It shows short-lived paid search ads using cloaking can let scammers impersonate crypto platforms to steal wallet approvals.

Overview

  • A Hyperliquid user lost about $550,019 in USDC after clicking a sponsored Google search result that redirected to a counterfeit Hyperliquid site, according to blockchain tracing posted by FlashRescue co‑founder DarcyAri.
  • On‑chain records show the stolen funds were split into three attacker‑controlled addresses, roughly 440,015 USDC, 82,503 USDC and 27,501 USDC, providing evidence that the money moved off the victim’s wallet.
  • Google confirmed it suspended the advertiser account tied to the malicious paid search ad after researchers flagged the campaign, and the suspension is the latest public response as of Aug. 14, 2026.
  • Security researchers and multiple reports say Hyperliquid’s smart contracts and on‑chain systems were not breached and that the attack used front‑end impersonation to capture wallet approvals or credentials.
  • The incident fits a wider pattern documented by SEAL and others in which attackers buy or hijack advertiser accounts and use cloaking to run short‑lived crypto phishing ads, so users are advised to use verified bookmarks, hardware wallets, and avoid clicking sponsored search results while investigators seek links from the recipient wallets to exchanges for possible recovery.