Key Highlights
- Hyperliquid users lost approximately $550,000 in a phishing incident involving Google paid advertisements on August 13.
- Three attacker addresses received USDC transfers totaling about $550,000 in a transaction linked to the incident.
- The attack follows similar phishing activity targeting Trezor users through sponsored Google search results earlier this month.
Hyperliquid users lost allegedly approximately $550,000 in a phishing attack involving fraudulent Google advertisements on August 13, according to blockchain data and a security researcher.
In an X post on Thursday, DarcyAri, co-founder of FlashRescue, flagged the incident, saying a Google paid-ad phishing campaign targeting Hyperliquid users resulted in the losses. Attacker’s reported addresses linked to the incident include: 0x98b2761559A348968C994D9856dCfc96B6f13C55, 0x93b6B24DC6E6a1D5d72399e3A35498c4DbA1d6D1, and 0x6fE314fD4CF845f35fc461eD98e2FB8d9356B566.

The transfer was made around 12 hours ago from the time of publication, including individual transfers of 27.501K USDC ($27.5K) to 0x6fE314…B566, 82.503K USDC ($82.5K) to 0x93b6B2…d6D1, and 440.015K USDC ($440.02K) to 0x98b276…13C55. The transaction hash was 0xd0920a30a4f2e554e9d3a73dbcc12e8fc825dd874f23bc79f2a476408a7a11b0.
However, Blockchain data alone does not establish how the funds were obtained or whether all of the transfers came from victims of the same campaign.
Moreover, the co-founder urged users to take care of their accounts to protect their assets, as Google paid ads phishing incidents are frequent.
Similar phishing activity involving hardware wallets
The Hyperliquid incident follows a separate phishing campaign involving Trezor users earlier this month. On August 7, 2026, Trezor issued a statement regarding an increase in phishing websites that impersonate its brand. Some of these sites appeared in sponsored search results on Google.
Trezor said the sites could appear convincing and warned that entering a wallet backup phrase on such a site could lead to the loss of funds. A Trezor user reported on X that the top sponsored Google result for the search term “Trezor wallet” led to a phishing site.
The campaign was separate from the recent data breach at Trezor’s third-party shipping provider, ShipMonk, which exposed personal information belonging to 13,689 customers.
Crypto users continue to face phishing risks
The Hyperliquid incident is also part of a broader pattern of attacks in which users are tricked into authorizing transactions or providing wallet credentials.
In July, a crypto user lost $999,999 in USDT after signing a phishing token approval on Ethereum, according to Web3 anti-scam firm Scam Sniffer. The attacker’s automated script initially attempted to transfer about $1 million before adjusting the amount after the first transaction failed.
Unlike attacks that exploit smart-contract approvals, search-ad phishing attempts target users before they interact with a legitimate platform. Fraudulent advertisements can direct users to cloned websites designed to collect login credentials, wallet information or transaction approvals.
Hyperliquid market activity in 2026
The incident comes as activity on Hyperliquid has continued to grow.
According to a quarterly report published by research firms Four Pillars and GLC Research, with support from Hyperliquid ecosystem groups, the HYPE token returned 79.2% during the quarter. The token reached an all-time high of $76.90 on June 16 and closed the quarter at $66.04. During the same period, Bitcoin declined 14.1 percent, marking its third consecutive negative quarter. Bitcoin has approximately halved from its peak recorded in October 2025.
HyperTracker, an analytics platform focused on the protocol, reported that the number of active perpetual traders on Hyperliquid reached 263,666 on August 6, 2026, recording a new high. This figure represented an increase of 486 traders, or 0.18 percent, over the previous 24 hours.
Data extending back to November 2025 shows the number of active traders rising from approximately 150,000 in early January 2026, with accelerated growth observed during the spring and summer months.
The reported phishing attack occurred against the backdrop of this broader increase in activity, but there is no indication that the incident affected Hyperliquid’s underlying protocol or its blockchain infrastructure.
Also Read: Metaplanet Launches BitBonds Program to Back its Bitcoin Strategy
