← News·Markets · Digital AssetsMarkets

Google ad phishing attack drains $550,000 from Hyperliquid user, security specialist says

A phishing campaign run through Google's ad network cost one Hyperliquid (HYPE) user $550,000, a security specialist said. Crypto security nonprofit Security Alliance (SEAL) flagged the same tactic in April, reporting…

NM
NewsMV Markets Desk
3 min read
14 August 2026Markets desk
Share this dispatch

Key takeaways

  • A phishing campaign run through Google's ad network cost a single Hyperliquid (HYPE) user $550,000, according to a security specialist.
  • Crypto security nonprofit Security Alliance (SEAL) said in April it had identified and blocked 356 malicious Google ad URLs over several weeks.
  • Google ads appear above organic search results, letting fraudulent placements intercept users before they reach the real site.
  • The total victim-side losses across SEAL's 356 blocked URLs remain unattributed, leaving the campaign's full scale unknown.
  • The $550,000 Hyperliquid case is the only documented victim-side loss figure in the record.

A phishing campaign run through Google's ad network cost one Hyperliquid (HYPE) user $550,000, a security specialist said. Crypto security nonprofit Security Alliance (SEAL) flagged the same tactic in April, reporting it had blocked 356 malicious Google ad URLs across several weeks. The aggregate victim-side loss across those URLs remains unattributed.

The Hyperliquid loss

The $550,000 figure covers a single user's exposure, attributed by a security specialist. Google ads sit above organic search results, giving fraudulent placements a position that intercepts users before they reach the real site. No wallet address, specific date, or further breakdown of the attack chain appeared in available reporting beyond the Google ad vector and the dollar amount.

SEAL's April action

SEAL, a crypto security nonprofit, said in April it had identified and blocked 356 malicious URLs running through Google's advertising system over several weeks. That count is the supply-side measure. It reflects fraudulent ad placements removed, not the number of users successfully defrauded before those links came down.

What to watch

A full accounting of losses across the 356 URLs SEAL blocked would put a real number on the campaign's scale. The one documented case on Hyperliquid at $550,000 is the only victim-side figure in the record.

Related reading

Categorycrypto

Filed via theblock.co

Keep reading

More from the markets desk

Frequently asked

How much did the Hyperliquid user lose in the phishing attack?

A security specialist attributed a $550,000 loss to a single Hyperliquid user, covering that one user's exposure.

How was the phishing attack carried out?

It was run through Google's ad network, where paid ads sit above organic search results and intercept users before they reach the legitimate site.

What did SEAL do about the malicious Google ads?

SEAL, a crypto security nonprofit, said in April it had identified and blocked 356 malicious URLs running through Google's advertising system over several weeks.

How many people were defrauded across the 356 blocked URLs?

That is unknown; the 356 count reflects fraudulent ad placements removed, not the number of users successfully defrauded, and the aggregate victim-side loss remains unattributed.

Were details like the wallet address or date of the Hyperliquid attack disclosed?

No; available reporting included only the Google ad vector and the $550,000 amount, with no wallet address, specific date, or further breakdown of the attack chain.