The stolen assets were distributed across addresses 0x98b276…13C55, 0x93b6B2…d6D1, and 0x6fE314…B566. While on-chain records confirm the movement of funds, the causal link to the Google advertisement relies on victim reports and researcher attribution. GoPlus Security independently corroborated the threat by identifying two of these addresses in its own database of malicious actors.
Google confirmed the suspension of the advertiser responsible for the campaign, citing a zero-tolerance policy toward scams. Despite these measures, bad actors continue to exploit the platform by purchasing verified accounts or using cloaking techniques to bypass automated safety filters. The Security Alliance (SEAL) has tracked this trend extensively, noting that it blocked over 356 malicious URLs in a recent campaign, including 17 sites specifically impersonating Hyperliquid.

Comments (0)
No comments yet. Be the first!