
A Hyperliquid user has lost about 550,000 USDC after a Google sponsored advertisement directed the victim to a fake version of the decentralized trading platform, with investigators linking the theft infrastructure to the Inferno drainer ecosystem.
Summary
- A Hyperliquid user lost about 550,000 USDC after clicking a Google sponsored ad for a fake website.
- Salus linked the attack infrastructure to the Inferno drainer ecosystem.
- The backend automatically split the stolen funds among addresses tied to the operation.
- Groups linked to the infrastructure were connected to about $52.74 million in losses.
Blockchain security firm Salus said in an Aug. 24 post on X that the theft took place on Aug. 13 and involved a counterfeit Hyperliquid website promoted through paid Google search results. After tracing the stolen funds and reviewing the infrastructure behind the page, the firm said it connected the operation to a professional drainer-as-a-service network associated with Inferno.
Hyperliquid phishing case used automated theft infrastructure
Salus said its undercover investigation found that the service solicited customers through the Telegram account @AngelFernoOwner. The operator advertised tools including malicious scripts, administrative panels, approval-command generation, one-time contract deployment, automated draining, cross-chain withdrawals, token swaps, and fund consolidation.
The service also offered “automated revenue sharing,” according to the security firm, allowing proceeds from successful phishing attacks to be divided among participants without manual transfers.
In the Hyperliquid case, Salus attributed separate roles to the phishing group and the backend service. The group bought the sponsored advertisements, deployed the spoofed Hyperliquid entry point, and supplied the address designated to receive the proceeds. Once the victim approved the malicious transaction and the funds were taken, the infrastructure handled the split automatically.
According to Salus, address 0x98b276…13C55 received 80% of the proceeds, while 0x93b6B2…1d6D1 received 15% and 0x6fE314…B566 received 5%. A fourth address, 0x9bcd…9104a, executed the drain.
Earlier reporting on the Aug. 13 incident showed roughly 550,019 USDC moving in three transfers of about 440,015 USDC, 82,503 USDC and 27,501 USDC to addresses identified by security researchers as attacker-controlled. Google later suspended the advertiser linked to the reported campaign, according to reports published after the theft.
Drainer-as-a-service model provides ready-made phishing tools
The setup described by Salus follows a model in which phishing operators can use ready-made wallet-draining infrastructure while concentrating on advertising, fake websites, and victim targeting.
As crypto.news explained in July 2026, wallet drainer services are built around malicious approvals that allow an attacker-controlled contract to transfer tokens after a user signs a transaction. The report also described drainer-as-a-service operations as an industry in which developers supply malicious software and share stolen proceeds with affiliates who bring in victims.
Such infrastructure can separate the visible phishing campaign from the software used to process approvals and move assets. In the latest case, Salus said the advertised package covered both the initial draining tools and later stages such as cross-chain withdrawals, swaps, consolidation, and profit distribution.
Inferno has been tied to other large approval-phishing cases. A May 2026 Coinbase lawsuit report covered an anonymous investor who alleged that about $55 million in DAI was stolen in August 2024 after the victim interacted with a fake login page. The complaint said the attacker used Inferno Drainer, while blockchain security firm Zero Shadow later traced part of the stolen assets to a Coinbase retail account.
Salus links infrastructure to $52.74 million in losses
Tracing beyond the Hyperliquid victim, Salus said groups connected to the infrastructure were linked to approximately $52.74 million in total losses across multiple phishing incidents.
One of the largest cases cited by the firm involved the attacker behind the September 2025 UXLINK exploit. On Sept. 23, 2025, the attacker later became the victim of an approval-phishing attack that moved roughly 542 million UXLINK tokens.
A September 2025 UXLINK phishing report said ScamSniffer detected a malicious increaseAllowance approval that enabled phishing addresses to drain more than $43 million worth of UXLINK at the time. SlowMist founder Yu Xian said the theft was likely carried out by Inferno Drainer using an authorization-phishing method.
The phishing incident followed the original UXLINK compromise one day earlier. Attackers had exploited a delegateCall vulnerability in the project’s multi-signature wallet, obtained administrator privileges, and moved about $11.3 million in assets, while unauthorized token minting caused further disruption. The later phishing theft removed hundreds of millions of UXLINK from the exploiter’s own wallet.
Salus also linked the infrastructure to an April 15, 2026 incident involving CoW.fi. According to the security firm, the protocol’s official domain was hijacked, and one associated victim lost about 316,000 USDC.
A third incident cited by Salus occurred on July 9, when a suspected fake decentralized application or fake airdrop prompted a malicious approval that resulted in the theft of 999,999 USDT. ScamSniffer had reported the transaction, according to the firm’s account of the case.
Evidence and high-risk addresses sent for action
The Hyperliquid case follows other phishing operations in which attackers copied recognizable crypto brands and used familiar online services or development platforms to place malicious pages in front of potential victims.
A March 2026 OpenClaw phishing report described attackers creating fake GitHub accounts and cloned websites before directing developers to malicious wallet-connection prompts. OX Security said the campaign used obfuscated code and targeted users with fake token offers, although no confirmed victims had been reported at the time.
For the Aug. 13 Hyperliquid theft, Salus said its investigation covered the subsequent fund flows, the service infrastructure and the accounts used to recruit phishing operators. The firm said all supporting evidence, identified high-risk addresses and related intelligence had been formally submitted to relevant organizations for risk labeling and coordinated action.


