A crypto trader lost approximately $550,000 in USDC after clicking on a fraudulent Google ad that impersonated Hyperliquid, the popular decentralized perpetual futures exchange. The phishing site, designed to look identical to the real platform, drained the victim’s wallet in what security researchers are calling yet another example of search engine advertising being weaponized against DeFi users.

The attack didn’t exploit any vulnerability in Hyperliquid’s smart contracts or on-chain infrastructure. It exploited something far simpler: human trust in Google search results.

How the scam worked

The attacker purchased a sponsored ad on Google that appeared when users searched for Hyperliquid. Sponsored results sit above organic search results, which means the fraudulent link was likely the first thing the victim saw. Clicking it redirected to a convincing replica of Hyperliquid’s interface, where the phishing site was engineered to steal wallet approvals or seed phrases.

Security researcher Darcy, co-founder of FlashRescue, flagged the incident and noted that the stolen funds, totaling roughly 550,019 USDC, were subsequently moved to three separate wallet addresses controlled by the attackers.