The co-founder of the chain security agency FlashRescue Darcy disclosed on August 13 that an encrypted user eventually lost approximately $550,000 USDC by clicking on a fake Google ad at Hyperliquid. Available information indicates that the problem is on the outside fishing page and there is no evidence that the Hyperliquid agreement itself was broken.

Money flows have been marked

Darcy published three addresses allegedly related to the attackers. The chain data show that approximately 550,019 USDCs were transferred to these addresses, divided into three main transfers: about 440,015 USDC, 82,503 USDC and 27,501 USDC.

Such incidents are usually not direct attacks on agreements, but lead to the linking of wallets and the signing of malicious transactions by first inducing users to access the wrong site by searching for advertisements, counterfeit pages or disguised entry points.

The attack is more like a user-end fishing.

FlashRescue also mentioned that some recent encryption asset theft tools would use the browser-end JavaScript to induce victims to complete their signature. Once authorized by the user, the assailant may transfer the assets from the wallet.

However, in the case of this Hyperliquid-related incident, there is currently no public evidence to confirm which of the techniques the attackers have specifically used. The information is known only to indicate that the victim was exposed to an external fishing station before entering the real platform.

There's no sign of a breach.

The public information at this stage does not show that the Hyperliquid agreement was breached or that there was evidence of a security gap in the Platform ' s core system. The incidents are more likely to be user-directed fraud around branding keywords, searches for entrance hijackings and page impersonations.

For users, such risks are mainly concentrated on access and signature links. Searching for advertisements, domain name details and wallet authorization is often the key to the attackers.