ADVERTISEMENT

Events

IAMTN Annual Summit 2026
14 Oct 26
London
Money20/20 USA 2026
18 Oct 26
Las Vegas

Salus Links $550K Hyperliquid Theft to Inferno Drainer

Blockchain security firm Salus has linked the August 13 theft of about $550,000 in USDC from a Hyperliquid user to professional phishing infrastructure associated with the Inferno Drainer ecosystem.

In an August 24 post on X, Salus said its investigation traced the stolen funds and examined the infrastructure behind a counterfeit Hyperliquid website promoted through Google sponsored search results. The firm said the operation was not a standalone phishing campaign but used a drainer-as-a-service network designed to automate the theft and distribution of crypto assets.

Fake Hyperliquid site used automated draining infrastructure

The attacker used a counterfeit Hyperliquid website to persuade the victim to approve a malicious transaction. The stolen funds were subsequently split across several addresses, with Salus identifying allocations of 80%, 15% and 5%, while another address executed the drain.

Salus said its investigation found that the phishing operators and backend infrastructure provider played separate roles. The operators handled advertising and the fake website, while the drainer service automated approvals, asset transfers, cross-chain withdrawals, token swaps and fund consolidation.

The firm also traced the service to the Telegram account @AngelFernoOwner, which allegedly advertised automated revenue-sharing for affiliates. Salus said the infrastructure has been associated with about $52.74 million in losses across several phishing incidents.

You may also like: Taiko Halts Bridge Operations After $1.7 Million Exploit

Google ads are becoming a crypto security risk

Paid search advertising creates a particularly effective entry point for crypto phishing because users often encounter sponsored results before organic links. Unlike traditional malware campaigns that require victims to install software, wallet-draining attacks can succeed when a user simply connects a wallet and signs what appears to be a routine transaction.

The model also lowers the technical barrier for attackers. Ready-made draining infrastructure allows phishing groups to focus on acquiring victims while third-party services handle the more complex movement and distribution of stolen assets.

For users, that means verifying a website address is no longer enough. A legitimate-looking search result, even when displayed prominently by a major platform, does not establish that the underlying crypto service is genuine.

What happens next

Salus said it submitted evidence, high-risk wallet addresses and related intelligence to relevant organizations for risk labelling and coordinated action.

Google reportedly suspended the advertiser associated with the campaign after the theft. The unresolved question is how quickly malicious advertisements can be detected before users interact with them.

The incident also puts attention on the broader Inferno-linked infrastructure. Salus has connected the same network to incidents involving UXLINK and CoW.fi, suggesting that disrupting the underlying service could have a wider effect than removing individual phishing websites.

For crypto users, the immediate lesson is practical: access trading platforms through verified domains or saved bookmarks rather than sponsored search results, and treat wallet approval requests as financial transactions that require careful verification.

 

Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights

Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.

ADVERTISEMENT
ADVERTISEMENT

Spotlight

-
00:00
00:00
Update Required Flash plugin
-
00:00
00:00