- A Hyperliquid user lost approximately 550,000 USDC after clicking a malicious Google-sponsored ad that redirected to a fake version of the decentralized trading platform.
- Blockchain security firm Salus linked the attack infrastructure to the Inferno drainer ecosystem, a known wallet-draining toolkit.
- The fake site likely prompted the victim to connect a wallet and approve malicious transactions, a common technique in crypto phishing campaigns.
- Google has faced repeated criticism for allowing fraudulent ads that impersonate legitimate crypto platforms, despite policy updates.
- The incident underscores persistent risks in crypto user security, where even savvy traders can fall victim to sponsored search results.
Phishing via Sponsored Search Results
A Hyperliquid trader suffered a significant loss of approximately 550,000 USDC after interacting with a fraudulent Google advertisement. According to blockchain security firm Salus, the sponsored link directed the victim to a counterfeit version of the Hyperliquid decentralized exchange (DEX). The fake interface was designed to mimic the legitimate platform, tricking the user into connecting their wallet and approving transactions that ultimately drained their funds. This incident highlights a growing trend where cybercriminals exploit search engine advertising to target crypto users, bypassing traditional email phishing in favor of more direct, trusted channels.
The attack infrastructure has been traced to the Inferno drainer ecosystem, a well-known wallet-draining service used by malicious actors. Inferno drainer is part of a broader category of “approval phishing” tools that allow attackers to steal tokens once a victim signs a malicious smart contract. Salus’s analysis indicates that the fake Hyperliquid site was hosted on infrastructure previously associated with Inferno, suggesting a coordinated or repeat use of the same toolkit. While the exact distribution method—whether via Google Ads or another vector—is under scrutiny, the sponsored ad appears to have been the entry point for the victim.
The Mechanics of Wallet Draining
Wallet drainers like Inferno operate by deceiving users into granting token approvals. When a user connects their wallet to a malicious decentralized application (dApp), the site requests permission to spend specific tokens. If the user signs the transaction without verifying the contract address, the attacker gains the ability to transfer those assets. In this case, the fake Hyperliquid site likely presented a familiar trading interface, lowering the victim’s guard. The 550,000 USDC loss is notable not just for its size but because it occurred on a platform known for its security-focused user base, indicating that even experienced traders are vulnerable to well-crafted phishing pages.
This incident is not isolated. Over the past year, multiple crypto platforms, including major names like Uniswap and Lido, have been impersonated via Google Ads. In several instances, users have lost millions of dollars collectively. Google has updated its advertising policies to restrict crypto-related ads, but enforcement remains inconsistent. Malicious actors often rotate domains and use cloaking techniques to evade detection, making it difficult for automated systems to block all fraudulent campaigns. The Hyperliquid case adds to a growing body of evidence that sponsored search results remain a high-risk vector for crypto theft.
Response and Mitigation Efforts
Following the incident, Hyperliquid’s team has not issued a public statement specifically addressing the loss, though the platform’s community channels have seen increased discussion about security best practices. Salus has published a detailed technical report on the attack, including wallet addresses and infrastructure indicators, to help other users identify potential threats. The firm recommends that users always verify the URL of any crypto platform before connecting a wallet, use hardware wallets for large holdings, and revoke token approvals for unused dApps via tools like Etherscan or Revoke.cash.
For the broader crypto ecosystem, this event serves as a reminder that phishing attacks are evolving beyond email. Sponsored ads on search engines carry an implicit trust signal, which attackers exploit to devastating effect. While decentralized platforms like Hyperliquid offer transparency and self-custody, they also place the full burden of security on the individual user. Until search engines implement stricter verification for crypto advertisers, users must treat every link—especially paid ones—with skepticism. The 550,000 USDC loss is a costly lesson, but it may prompt more robust community-driven safeguards and educational initiatives to prevent similar incidents in the future.











Comments are closed.