google-news-img
spot_img
spot_imgspot_imgspot_imgspot_img

Did You Just Google ‘Hyperliquid’? You Might’ve Landed on a Wallet Drainer

  • A fake Hyperliquid ad on Google is draining user wallets via malicious approvals.
  • Victims are lured through near-perfect domain clones like app.hyperliquid.xyz-trade.foundation-s1.eu.com.
  • This isn’t isolated: scam ads caused over $494M in wallet thefts in 2024, mostly via Google and Twitter links.

A malicious ad impersonating Hyperliquid has surfaced on Google, tricking DeFi users into connecting wallets and signing away their assets.

These attacks rely on precision-cloned domains and malicious smart contract approvals; no seed phrase needed.

Scam Sniffer confirmed the exploit is live, with real user funds at risk. The bigger story? This is part of a rising trend: wallet drainer scams now eclipse protocol hacks in total value stolen.

These Google ad-based exploits are part of a growing trend known as Pig Butchering, where scammers create fake dashboards or investment fronts to “fatten” users before draining their wallets through deceptive permissions.

According to Scam Sniffer, these scams aren’t isolated: wallet drainers have drained $494 million from over 300,000 wallets in 2024, a 67 percent year-over-year increase.

Sophistication in Scale: Cloned Domains and Fake Branding

Scammers are cloning official Web3 project domains and matching tired branding to deceive even discerning users.

These look-alike sites reproduce layout, naming, and interaction flows to create a false sense of legitimacy.

In the case of Hyperliquid, the site mimics the official interface enough to lure users into granting “approval” permissions — an action that executes a smart contract draining assets under the radar.

Hyperliquid scam: Source: X

This attack vector has become the dominant threat model in DeFi, surpassing protocol hacks.

Notably, Scam Sniffer reported 30 wallet‑drainer scams in 2024. The total amount exceeded $1 million, with the largest single theft netting $55.4 million.

Ethereum was the primary target, accounting for more than $152 million, nearly 89 percent of the total loss from large-scale drainers.

Beyond the Phishing Trap: No Seed Phrases, Just Signatures

Unlike traditional wallet phishing that steals seed phrases, these auto-drainers rely on malicious smart contract approvals.

Users land on the cloned site, connect their wallet through WalletConnect or injected Web3 libraries, and approve transactions; often with subtle permissions like “collectibles” or “manage assets.”

Once signed, billions of dollars pass through, sometimes behind the scenes, in seconds.

Check Point Research recently exposed a similar mobile attack: a fake WalletConnect app on Google Play gathered over 10,000 installs, siphoning around $70,000 in crypto. That malware evaded detection for five months, demonstrating the sophistication of the latest threats.

This isn’t an isolated case: similar fake ads for Solscan (April 26) and Aave (June 20) also topped Google results, as flagged by Scam Sniffer, using identical wallet-drainer tactics.

When Wallet Drainers Outpace Hacks

In 2024, wallet drainer scams alone cost victims nearly $494 million, approaching total losses from DeFi hacks and bridge exploits.

Unlike high-profile hacks, drainers target individuals across the spectrum, strategically scaling up success by the sheer number of compromised wallets.

This marks a fundamental shift in risk: losses now arise from exploitative UX and deceptive web practices, not just code vulnerabilities

What This Means for Users and Platforms

Crypto users must now scrutinize URLs, even when they appear official. Verifying domain authenticity, avoiding ads for direct wallet connections, and checking token approvals are essential.

Web3 infrastructure providers should also enforce additional UX barriers, like transaction confirmation warnings and approval notifications.

Top crypto crimes in 2024: Medium

Monitoring and analytics solutions deserve fresh attention. As Scam Sniffer and Chainalysis confirm, wallet-drainer (pig butchering) attacks are the largest single source of wallet theft in 2024.

Disclaimer

The contents of this page are intended for general informational purposes and do not constitute financial, investment, or any other form of advice. Investing in or trading crypto assets carries the risk of financial loss. The forecasted data (also called “price prediction”) on this page are subject to change without notice and are not guaranteed to be accurate.

Our Newsletter

Subscribe to our newsletter to get the latest news and promotions.

Rahul Nambiampurath
Rahul Nambiampurath
Rahul Nambiampurath's cryptocurrency journey began in 2014 when he stumbled upon Satoshi's Bitcoin whitepaper. With a bachelor's degree in Commerce and an MBA in Finance from Sikkim Manipal University, he was among the few who first recognized the untapped potential of decentralized technologies. Since then, he has helped DeFi platforms like Balancer and Sidus Heroes — a Web3 metaverse — as well as CEXs like Bitso (Mexico's largest) and Overbit reach new heights with his media outreach skills and digital marketing strategies. For the past eight years, he has also covered major crypto events for leading publications — including Investopedia, Crypto Briefing, FXEmpire, Crypto.news, The Defiant, and BeInCrypto — with expertise spanning DeFi, DAOs, NFTs, and everything decentralized.