In another episode of scams that made headlines in 2026, a recent phishing attack specifically targeted Hyperliquid users rather than a direct breach of Hyperliquid’s protocol.
According to Darcy Ari, co-founder of FlashRescue, on the 13th of August, the attackers used Hyperliquid-related keywords to buy Google Search advertisements.
In the background, the malicious advertisement may have shown up among the top results when users searched for the platform, possibly passing for an official Hyperliquid link.
Following which, at least one user was sent to a phony website that mimicked the genuine platform after clicking on the advertisement.
Funds drained
That said, the user seemed to have lost 550,019 USDC, or about $550,000. After that, the money was moved to three blockchain addresses that were purportedly connected to the attackers.
In this transfer, around 440,015 USDC, 82,503 USDC, and 27,501 USDC were moved, respectively.


For context, instead of relying on a technological breach at Hyperliquid, the alleged attack used social engineering.
In order to trick users into connecting wallets, authorizing malicious transactions, or disclosing private information, attackers allegedly made a phony Hyperliquid website and advertised it using Google Search ads.
After being provided access, the attackers were able to transfer money without jeopardizing the trustworthy platform.
Steps taken
It has been reported that Google suspended the campaign’s associated advertiser. Well, this isn’t the first time a search ad-based crypto phishing attack has happened.
Given the rise in such scams, the Security Alliance (SEAL) has previously discovered over 356 malicious advertising URLs that target cryptocurrency wallets and platforms.
Attackers are stepping up their game
This comes as South Korean cybersecurity company Genians has reported that Kimsuky, a hacker collective with ties to North Korea, is allegedly incorporating AI tools straight into its cyberattack infrastructure.
The action may enable Kimsuky to automate and scale certain aspects of its attacks, including target research, phishing content creation, information analysis, and support for other phases of cyber operations.
Final Summary
- The attackers used Hyperliquid-related keywords to buy Google Search advertisements, which forced one user into a phony website.
- SEAL has previously discovered over 356 malicious advertising URLs that target crypto wallets and platforms.




Be the first to comment