Breaking
August 14, 2026

Attackers rent verified Google ad accounts to hide Hyperliquid clones behind nested iframes Randa Moses | usagoldmines.com

A paid Google search ad directed a Hyperliquid user to a fake version of the exchange, causing them to lose about $550,000 in USDC, according to FlashRescue co-founder Darcy.

Darcy flagged the theft in a post Thursday, pointing to blockchain records that map the money’s exit.

What the on-chain trail shows

Data from Arkham Intelligence revealed three USDC transfers under one transaction hash. The bulk of it, some $440,000, went to 0x98b276…13C55.

There were two other smaller transfers, of about $82,500 and $27,500, to 0x93b6B2…d6D1 and 0x6fE314…B566, respectively.

Google shut down the account behind the ad. Scammers have used paid search against DeFi users since 2020, when fake Balancer and Uniswap ads went after private keys and wallet approvals.

Why do search ads keep slipping through?

Security Alliance (SEAL), a crypto-security nonprofit, explained how ads get past Google’s checks.

Hackers buy or steal verified Google advertiser accounts. Then they provide Google with a clean webpage hosted on a trusted domain.

When clicking on the ad, the webpage behaves in two different ways. If the visitor is a potential victim, it loads a fake DeFi exchange page. If it’s a security researcher, the page loads a Wikipedia page, and there’s nothing to report about.

Once the victim falls for the fake DEX, they connect their wallet and sign, and the drainers steal all their crypto assets.

SEAL reported finding drainers from Inferno Drainer and Vanilla Drainer malware families.

Over a few weeks, SEAL blocked 356 malicious ad URLs, several of which posed as Hyperliquid. It cautioned users that an ad is frequently active “for only minutes before finding its first victim.”

SEAL advises DeFi users to skip Google Search for crypto apps and use bookmarks or an index like search.defillama.com.

Cryptopolitan previously reported that fake Uniswap ads stole $400,000+ from users. During the incident, around 146 Ether coins were pooled into two hackers’ addresses, which SEAL tied to $1.27 million in total phishing losses during March.

In July, Scam Sniffer found a user who lost $999,999 in USDT to a phishing approval on Ethereum.

Trezor had warned about lookalike sites in sponsored search results recently. Last November, Cryptopolitan flagged a fake Hyperliquid app on the Google Play Store.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It’s free.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.