A Hyperliquid trader lost $550,000 due to a phishing ad on Google.
A significant loss of funds occurred on the Hyperliquid platform: a trader lost approximately $550,000 in USDC after clicking a malicious link placed in Google ad results. The incident once again demonstrates that even experienced users of decentralized exchanges remain vulnerable to classic social engineering methods.
Attack Mechanics
The attackers created a fake website that fully mimicked the Hyperliquid interface. The phishing ad was placed in Google search results, giving it an appearance of legitimacy. The victim, trusting the look of the resource, interacted with the interface, after which funds were automatically withdrawn to the attackers' wallet.
Such schemes are nothing new to the crypto industry, but their effectiveness continues to grow. Attackers actively use paid advertisements to promote malicious domains, and users often fail to check URLs before connecting their wallets or confirming transactions.
Takeaways for DeFi Users
This case underscores the critical importance of domain verification and the use of hardware wallets with additional confirmation layers. Even when clicking a link from a search engine, it is necessary to manually check the site's address, as well as pay attention to SSL certificates and the domain's history.
For platforms like Hyperliquid, aimed at advanced traders, the incident serves as a signal to strengthen educational measures and implement stricter mechanisms for warning about suspicious activity.
My comment: The $550,000 loss is a painful but instructive lesson. In the DeFi environment, where responsibility lies entirely with the user, phishing remains one of the most underestimated risks. I recommend that all traders adopt a "double-check" rule: never click on ad links and always manually save critical domains in browser bookmarks.