Google Ads phishing: fake Hyperliquid is not a protocol hack
We reviewed a 24 Jul X amplification (@CryptocapoOO) claiming Hyperliquid was being “hacked” via Google: search the brand → top Sponsored result → clone site → connect wallet → funds gone, “hundreds” emptied. Our check: the Google Ads → pixel-clone → approve/permit drain pattern is real and well documented for Hyperliquid (and Uniswap/Aave/Jupiter-class brands) across 2025–2026, with brand-impersonation domains still flagged in Jul 2026. Framing it as an Hyperliquid L1/app exploit is wrong — users are phished; contracts are not the breach. “Hundreds emptied this week” stays unverified without a firm address table. Official app to bookmark only: app.hyperliquid.xyz — never open from Sponsored results.
369 take: Sponsored search is not the official site. Same gun hits Pulse dApps and wallets — bookmark the canonical URL, ignore ads, and read every approval. If you already connected a fake front end, revoke allowances and move funds from a clean bookmark only. This is phishing, not “the protocol got hacked.”