Crypto news

14.08.2026
09:05

Phishing via Google: Hyperliquid trader loses $550,000 on a fake exchange

SCAM 2

Once again, a phishing attack via search advertising has led to significant financial losses for the crypto community. This time, the victim was a Hyperliquid trader who lost about $550,000 in USDC. The incident occurred after the user clicked on a Google ad that led to a fake website visually replicating the decentralized exchange's interface.

Attack Mechanics: How Scammers Deceived the System

The scheme used by hackers is not new, but it remains frighteningly effective. The fake resource was placed in Google's advertising network, allowing it to appear at the top of search results, masquerading as the official Hyperliquid domain. As soon as the trader clicked the link and began interacting with the interface—such as connecting a wallet or authorizing transactions—a malicious script intercepted the data and initiated withdrawals to the scammers' addresses.

It is important to emphasize that such attacks exploit not a technical vulnerability in the blockchain, but the human factor and trust in search engines. Despite its moderation algorithms, Google does not always manage to promptly block fraudulent ads, creating a window of opportunity for criminals.

Lessons for DeFi Users

This case is yet another reminder of the critical importance of verifying URLs before any actions involving assets. Even if a website looks identical to the original, you should always manually check the domain, use bookmarks, or hardware wallets with additional signature verifications. In the world of decentralized finance, where there is no insurance or refund mechanism, vigilance is the only line of defense.

In my view, the industry needs to more actively implement solutions at the browser and wallet level that automatically detect phishing domains in real time. For now, users should avoid clicking on ad links in search engines, preferring to enter addresses directly or use trusted aggregators. The loss of $550,000 is not just a number, but a signal to the entire community that security begins with habits, not technologies.