Reported $550K USDC Loss After Clicking a Google Sponsored Link
A Hyperliquid user reportedly lost about 550,019 USDC on Aug. 13 after interacting with a phishing website that appeared through a paid Google search result, according to FlashRescue co-founder Darcy. On-chain records show the funds were split across three addresses, providing clear evidence the tokens moved — but blockchain data alone cannot prove how the user was duped.
On-chain movements and addresses tied to the incident
Blockchain transfers linked to the incident show the approximately 550,019 USDC split into three sums: roughly 440,015 USDC, 82,503 USDC and 27,501 USDC. The recipient addresses flagged in public reports are 0x98b276…13C55, 0x93b6B2…d6D1 and 0x6fE314…B566. Security researchers including FlashRescue and GoPlus Security identified these addresses during their rapid response and alerting.
Although these on-chain transactions confirm funds were drained, investigators caution that on-chain traces do not by themselves establish the origin of the compromise. Attribution to a Google advertisement rests on researcher reporting and victim testimony rather than the immutable blockchain ledger alone.

How researchers linked the theft to a Google ad
Darcy and other analysts say the user was likely redirected to a phishing site via a sponsored Google search result that impersonated Hyperliquid. Security Alliance (SEAL) and FlashRescue both emphasize that malicious actors often use hacked or fraudulently purchased verified advertiser accounts, cloaking, and browser fingerprinting to slip past automated ad screening.
SEAL’s monitoring found dozens of malicious advertising URLs during a recent campaign; the group reported blocking more than 356 malicious ad links in a matter of weeks and cataloged 17 Hyperliquid-impersonation domains among its dataset. However, SEAL also stresses reliable attribution to a specific advertisement requires direct victim evidence and further indicators of compromise.
Google response and advertising safety context
Google told media outlets it suspended the advertiser involved in the reported campaign and reiterated it has “zero tolerance for scams.” The company highlighted that its systems stopped more than 99% of policy-violating ads before they reached users in 2025. Google’s 2025 Ads Safety report noted the platform blocked or removed over 8.3 billion ads and suspended 24.9 million advertiser accounts globally, including millions tied to scams.
While those enforcement figures show scale, they do not directly confirm the mechanism in this Hyperliquid case. Google’s suspension of the specific advertiser is a parallel development noted in public reporting.
Wider trend: sponsored search results used in crypto phishing
This reported Hyperliquid loss fits a broader pattern: threat actors increasingly weaponize sponsored search results to funnel victims to fake wallets and phishing dApps. Earlier incidents included fake Uniswap advertisements tied to losses of at least $400,000 in May and multiple reports where sponsored results mimicked Trezor and other wallet providers.
SEAL estimates $1.27 million in confirmed and unattributed losses tied to suspected malicious Google ads during a focused window in March, underscoring the recurring risk to retail crypto users who rely on search results rather than verified bookmarks.
How attackers evade detection
Reportedly, attackers use a mix of tactics to bypass ad platform controls: cloaking (showing benign content to scanners and malicious pages to real users), browser fingerprinting to detect automated checks, and secondary frames that deliver malicious payloads after an initial, harmless-looking landing page.
These techniques complicate automated defenses and make manual user vigilance essential. SEAL and other defenders recommend avoiding sponsored search results for crypto apps and instead relying on verified bookmarks or official links distributed by the project.
No evidence of a Hyperliquid protocol breach
Available information indicates the compromise targeted the user via an impersonation site rather than exploiting any vulnerability in Hyperliquid’s smart contracts or trading infrastructure. Hyperliquid’s documentation already warns users to verify full URLs and treat unknown wallet activity — unauthorized transactions, missing funds, or unexpected multisig changes — as signs of compromise.
Practical steps for users and investigators
- Verify full domain URLs and avoid clicking sponsored search results when accessing wallets, exchanges or decentralized apps.
- Use browser bookmarks or type official domains directly to reduce phishing exposure.
- Revoke suspicious token approvals and review transaction history in wallet explorers immediately after any unexpected prompt.
- Consider hardware wallets and multisig setups to limit single-point compromises.
- If funds are stolen, note the recipient addresses and timestamps; these on-chain indicators are crucial for forensic tracing and for contacting potential custody points like centralized exchanges or bridges.
What comes next
As of Aug. 14, the three recipient addresses remain publicly traceable on-chain and Google reportedly suspended the advertiser linked to the campaign. There were no public law enforcement filings or reported asset recoveries tied specifically to this case in the reviewed sources. The next verifiable progress would be movement from the flagged wallets or identification of an upstream service — an exchange, bridge, or mixer — that could provide investigative leads.
For now, the loss of approximately $550,000 is supported by on-chain transfers; the claim that a Google advertisement directly enabled the theft stems from FlashRescue’s research and the victim’s account. This event highlights the persistent risk of crypto phishing through paid search channels and the importance of layered user defenses when managing USDC, wallets and on-chain assets.





Discussion
Leave a Comment
Comments (2)
I've seen this in support threads, ppl trust search results too much. bookmarked sites and hw wallet wouldve stopped that. ugh brutal loss
Wait, a Google ad funneled someone to a fake Hyperliquid page and 550k gone? sounds sketchy, how did that slip past screening, cloaking probs. on-chain shows movement, but need victim logs