A Hyperliquid user appears to have lost roughly 550,019 USDC on Aug. 13 after interacting with a phishing site that was allegedly promoted through a Google search advertisement. The reported loss was flagged by FlashRescue co-founder Darcy, while on-chain transfers show the funds leaving the victim’s wallet in three separate movements.

The available blockchain data support the size and timing of the transfers, but they do not by themselves prove how the victim was tricked. The claim that the theft stemmed from a paid Google ad impersonating Hyperliquid remains based on the researcher’s attribution rather than on-chain evidence.

Three transfers traced on-chain

According to the reported findings, the stolen funds were split into three USDC transfers totaling about 550,019. The amounts were approximately 440,015 USDC, 82,503 USDC, and 27,501 USDC.

The transfers were sent to three recipient addresses identified as 0x98b276…13C55, 0x93b6B2…d6D1, and 0x6fE314…B566. SEAL also referenced two of the same addresses in its warning, adding another public signal tied to the reported incident.

Alleged phishing route through a search ad

Darcy said the user was likely redirected to an impersonating website through a Google search advertisement that presented itself as Hyperliquid. That would place the compromise before the victim reached the legitimate platform, rather than inside Hyperliquid’s own systems.

The distinction matters because the currently available evidence does not indicate any breach of Hyperliquid’s blockchain or trading protocol. Instead, the case appears consistent with a phishing setup designed to capture a user before they interact with the real service.

Google takes down the advertiser

Google said it suspended the advertiser linked to the campaign. The company also said it has zero tolerance for scams and that its systems blocked many ads that violated policy.

Hyperliquid did not immediately respond to requests for comment, according to the report. In its own documentation, the platform warns users to verify full URLs and to treat unfamiliar wallet activity as a possible sign of compromise.

What is confirmed so far

As of Aug. 14, no law enforcement action or asset recovery had been publicly announced in connection with the reported loss. The three destination addresses remain visible on-chain.

At this stage, the clearest confirmed element is the movement of roughly $550,000 in USDC. The connection to a Google ad is the reported explanation from the researcher and is supported by public warnings, but it is not something that blockchain records alone can conclusively establish.

Source: crypto.news