A Hyperliquid user reportedly lost around $550,000 in USDC after allegedly interacting with a phishing website that was promoted through a Google search advertisement.
According to security researcher and FlashRescue co-founder Darcy, the stolen funds were transferred to three separate wallet addresses believed to be controlled by the attackers.
Blockchain data shows that approximately 550,019 USDC was moved from the victim’s wallet and split among the three addresses. While the transfers confirm that the funds were moved, blockchain records alone cannot determine exactly how the theft occurred. The claim that the loss resulted from a phishing advertisement is based on the findings of security researchers and reported victim evidence.
The incident has raised fresh concerns about crypto-related phishing campaigns that use paid search advertisements to impersonate legitimate platforms. In this case, the fake website reportedly appeared in Google search results and was designed to resemble Hyperliquid.
Google said it suspended the advertiser linked to the reported campaign after being notified of the issue. The company stated that it maintains strict policies against scams and continuously removes fraudulent advertisements and advertiser accounts from its platform.
Security experts noted that similar phishing campaigns have targeted other cryptocurrency platforms in recent months. Attackers often use compromised advertiser accounts and fake websites that closely mimic legitimate services in an attempt to trick users into connecting wallets or revealing sensitive information.
There is currently no evidence that Hyperliquid’s blockchain, protocol, or trading infrastructure was compromised. The reported theft appears to have resulted from a phishing attack targeting the user rather than a security breach within the platform itself.
Hyperliquid has long advised users to carefully verify website addresses and avoid interacting with unknown links. Security specialists also recommend using bookmarked official websites rather than relying on search engine results when accessing cryptocurrency platforms.
As of now, no public information has been released regarding the recovery of the stolen funds. The wallet addresses involved remain visible on the blockchain, allowing investigators and security firms to continue monitoring the movement of the assets.
The incident serves as another reminder of the growing threat posed by phishing scams in the cryptocurrency industry, where attackers increasingly use sophisticated tactics to impersonate trusted brands and steal digital assets.







