NewsCryptoHyperliquid user loses $550,000 in USDC to fake exchange promoted through paid Google ad

Hyperliquid user loses $550,000 in USDC to fake exchange promoted through paid Google ad

Author: Cryptopolitan·

Key Takeaways

  • A Hyperliquid user lost approximately $550,000 in USDC after a paid Google search advertisement directed them to a counterfeit version of the exchange.
  • On-chain data from Arkham Intelligence showed three USDC transfers bundled under one transaction hash, with roughly $440,000, $82,500, and $27,500 sent to three different addresses, and Google has since shut down the responsible advertiser account.
  • SEAL blocked 356 malicious ad URLs over several weeks, several of which posed as Hyperliquid, and linked the activity to the Inferno Drainer and Vanilla Drainer malware families.
  • Because victims sign the malicious wallet approvals themselves, drainers can empty a wallet without ever obtaining the private key, and malicious ads are often live for only minutes before finding a first victim.
  • Hyperliquid has been impersonated in both sponsored search results and a fake Google Play Store app, and SEAL advises DeFi users to use bookmarks or an index such as search.defillama.com instead of Google Search.
Hyperliquid user loses $550,000 in USDC to fake exchange promoted through paid Google ad

A Hyperliquid user lost approximately $550,000 in USDC after a paid Google search advertisement directed them to a counterfeit version of the exchange, according to FlashRescue co-founder Darcy, who flagged the theft in a post on Thursday, citing blockchain records that trace the money's exit. Hyperliquid is a decentralized exchange best known for perpetual futures trading and runs on its own Layer 1 blockchain; USDC, a US dollar-pegged stablecoin issued by Circle, serves as the collateral traders post for margin on the platform, so large balances of the token commonly sit in user wallets.

What the on-chain trail shows

Data from Arkham Intelligence, an on-chain analytics platform, revealed three USDC transfers bundled under a single transaction hash. The largest, roughly $440,000, went to the address 0x98b276…13C55. Two smaller transfers followed — approximately $82,500 and $27,500 — destined for 0x93b6B2…d6D1 and 0x6fE314…B566, respectively.

Google has since shut down the advertiser account behind the promotion. Paid search attacks against DeFi users date back to 2020, when fake Balancer and Uniswap advertisements went after private keys and wallet approvals.

Why search ads keep slipping through

Security Alliance (SEAL), a crypto-security nonprofit, has explained how such ads evade Google's checks. Attackers buy or steal verified Google advertiser accounts, then supply Google with a clean webpage hosted on a trusted domain. Those verified accounts are worth acquiring because Google requires advertisers promoting cryptocurrency exchanges and wallets to be certified under its financial products policy, and a vetted account lends a malicious promotion an appearance of legitimacy.

Once a visitor clicks the ad, the page behaves in one of two ways. A prospective victim is served a fake DeFi exchange page, while a security researcher is shown a Wikipedia page — leaving nothing to report. When a victim interacts with the counterfeit DEX, they connect their wallet and sign, at which point the drainers steal all of their crypto assets. Because the theft runs through approvals the victim signs themselves, a drainer can empty a wallet without ever obtaining the private key.

SEAL reported finding drainers from the Inferno Drainer and Vanilla Drainer malware families. Over several weeks, the organization blocked 356 malicious ad URLs, several of which posed as Hyperliquid. It cautioned that an ad is frequently active "for only minutes before finding its first victim." SEAL advises DeFi users to skip Google Search when looking for crypto apps and to rely instead on bookmarks or an index such as search.defillama.com.

A recurring threat

Cryptopolitan previously reported that fake Uniswap ads stole more than $400,000 from users. During that incident, around 146 Ether was pooled into two hackers' addresses, which SEAL tied to $1.27 million in total phishing losses during March.

In July, Scam Sniffer found a user who lost $999,999 in USDT to a phishing approval on Ethereum. Trezor has also warned about lookalike sites appearing in sponsored search results. Last November, Cryptopolitan flagged a fake Hyperliquid app on the Google Play Store. The platform has now been impersonated across both sponsored search results and official-looking app listings, which means placement on either surface is not proof of authenticity.