A hacker used a sponsored Google search ad impersonating Hyperliquid to lure users to a phishing site, resulting in an estimated $550,000 in losses, according to on-chain investigator DarcyAri as reported by Wu Blockchain. The attack placed a fraudulent listing above Hyperliquid's genuine search result, a tactic that has become one of the most persistent threats facing the platform's users over the past year.

The mechanics are consistent with prior campaigns: victims searching for Hyperliquid on Google are shown a paid ad that looks identical to the legitimate site, click through to a near-perfect clone, and are prompted to connect their wallet or sign a transaction that drains their holdings. Because the fraudulent listing appears above organic search results and carries Google's own ad styling, even cautious users have been caught out.

Fake Hyperliquid Google Ad Drains About $550,000 From Users
Image via @WuBlockchain on X

Not an isolated incident

Hyperliquid has become a recurring target for this style of attack. Security researchers have separately traced a fake Hyperliquid app distributed through the Google Play Store to more than $281,000 in stolen funds, and similar Google Ads phishing campaigns impersonating other DeFi platforms — including one targeting Uniswap users that netted attackers over $400,000 — have followed the same playbook of buying ad placement above the real site.

Related: Whale Loses $26M in Private Key Breach, Two Years After a $24M Phishing Hit

Google has periodically cracked down on unverified financial-services advertisers, but attackers have continued to find ways around the platform's ad-review process, often by briefly running legitimate-looking campaigns before switching in malicious landing pages. For now, the most reliable defense remains avoiding search ads entirely and navigating to platforms like Hyperliquid via bookmarked or directly typed URLs rather than clicking the first result that appears.