Attackers are said to be renting verified Google advertiser accounts to mask cloned Hyperliquid sites inside nested iframes.
A new phishing scheme targeting users of the decentralized exchange Hyperliquid has been reported by Cryptopolitan and Yahoo Finance. According to the reports, attackers are renting verified Google advertiser accounts rather than creating their own. That approach lets scam campaigns appear under an account that has already cleared Google’s identity checks.
The cloned sites reportedly use nested iframes to conceal their true content. An iframe embeds one webpage inside another. Layering several of them can hide a malicious login page or wallet-connection prompt from automated ad review tools. To a casual visitor, or to Google’s scanning systems, the outer layer can look like a legitimate Hyperliquid interface.
Because the advertiser account carries Google’s verified badge, the resulting search ads can appear trustworthy to users searching for Hyperliquid. Verified badges are meant to signal that an advertiser’s identity has been checked. When that badge sits atop a rented account controlled by scammers, the signal loses its intended meaning.
Yahoo Finance reported that one trader lost $550,000 after interacting with a scam site tied to this campaign. The report did not detail the exact mechanism by which the funds were taken, but such losses in similar schemes typically follow from connecting a wallet to a fraudulent interface or approving a malicious transaction.
Hyperliquid has grown rapidly as a venue for on-chain perpetual futures trading, drawing significant trading volume and a large user base. That popularity makes it an attractive target for impersonation. Search advertising remains one of the most common entry points users take when looking for a trading platform, which is precisely what this scheme is reported to exploit.
The use of rented verified accounts marks an evolution in tactics compared with earlier crypto phishing campaigns. Rather than building fake credibility from scratch, attackers reportedly buy access to accounts that already have it. Combined with nested iframes designed to defeat automated screening, the technique appears aimed squarely at platforms meant to catch fraudulent ads before they reach users.
The reported scheme does not directly affect Hyperliquid’s protocol, token, or trading infrastructure, since the exploited weakness sits in Google’s advertising system rather than in the exchange itself. Even so, repeated impersonation campaigns can erode user trust in a platform’s brand and complicate efforts by legitimate projects to advertise safely.
For the wider industry, the case underscores a persistent gap between ad-platform verification processes and the realities of crypto phishing. Exchanges and DeFi platforms may face renewed pressure to warn users through official channels and to monitor search results for impersonating ads.
The reported losses highlight how verification badges and ad platform checks can be circumvented by determined attackers. Users searching for crypto platforms are advised to verify website addresses independently rather than relying solely on search ad placement.
Hyperliquid is a decentralized exchange focused on on-chain perpetual futures trading, which has attracted a large user base and significant trading volume.
Reports describe attackers using rented, verified Google advertiser accounts combined with nested iframes, a technique that layers webpages to obscure malicious content from automated review.
Yahoo Finance reported that one trader lost $550,000 after interacting with a scam site tied to the campaign.
The reports describe an advertising and phishing scheme impersonating Hyperliquid, not a breach of the exchange’s own infrastructure.
Verifying website URLs directly rather than clicking search ads, and avoiding wallet connections on unfamiliar sites, are commonly recommended precautions against this type of phishing.
Original source: AltcoinGordon