Cryptocurrency Trader Loses $550,000 to Phishing Site Promoted via Google Ads
A trader on the Hyperliquid platform lost $550,000 after accessing a phishing site displayed in Google search ads. Cryptocurrency-related phishing attacks using malicious Google advertisements are increasing significantly, with security experts warning users to avoid search engines and verify official URLs carefully.
How the Scam Works
A trader searching for the "Hyperliquid" cryptocurrency platform clicked on a fake website displayed in Google search advertisements. The fraudulent site impersonated the legitimate platform, and when the victim entered login credentials, attackers gained access to the account. Through three simultaneous transactions, approximately $550,000 in USDC stablecoins were transferred to attacker-controlled wallets.
The Growing Threat
According to security organization SEAL, phishing sites advertised through Google ads targeting DeFi applications, cryptocurrency wallets, and related services have increased "significantly" since the start of the year. In April alone, over 356 fraudulent URLs were blocked. Attackers focus on the most-searched cryptocurrency protocols, finding their first victims within minutes, and continue their campaigns despite blocking efforts because the financial gains are substantial.
Warning Signs and How to Spot Fakes
Characteristics of phishing sites:
- Marked as "Ads" in Google search results from non-official domains
- URLs with slight character variations or misspellings compared to official versions
- Requests for excessive information before login
- Lack of HTTPS encryption or proper SSL certificates
Verification methods to prevent fraud:
- Bookmark official websites - Save verified official links and access only from bookmarks
- Verify URLs character-by-character - Confirm every letter matches exactly
- Use trusted cryptocurrency directories - Access platforms through DefiLlama, CoinGecko, or CoinMarketCap after verifying their URLs
- Avoid using search engines for crypto apps - Find platforms through official community channels and documentation instead
Prevention Tips
Daily security practices:
- Use browser extensions that block known phishing sites
- Enable two-factor authentication (2FA) on all accounts
- Regularly clear browser cache and cookies
- Consider using a VPN for additional security
Cautious behavior when accessing sites:
- Never transfer large amounts on new or unverified sites
- Check for suspicious activity immediately after logging in
- Review all transaction details before confirmation
- Use a hardware wallet for storing significant amounts
Where to Report
If victimized, report to:
- Your cryptocurrency exchange - Request transaction blocks and fraud investigation
- Google Abuse Report - Report fraudulent advertisements
- FBI IC3 (for US residents) - Internet Crime Complaint Center
- Local law enforcement - File an official report with your jurisdiction
- Blockchain investigation firms - Request on-chain analysis to trace assets (limited success rates)
Source: Cryptoast