A Hyperliquid user lost about 550,000 USDC after clicking a sponsored Google advertisement that led to a counterfeit version of the decentralized trading platform. Security researchers said the theft infrastructure behind the incident appears to be connected to the Inferno drainer ecosystem.
The case highlights a phishing model in which one group handles advertising and fake websites while a separate backend service manages wallet approvals, asset draining and the distribution of stolen funds.
Phishing ad led victim to spoofed platform
The incident was previously reported as taking place on Aug. 13. According to earlier reporting cited in the source article, roughly 550,019 USDC was moved in three transfers of about 440,015 USDC, 82,503 USDC and 27,501 USDC to addresses that security researchers identified as controlled by the attackers.
The victim is reported to have reached the malicious site after clicking a Google sponsored ad that imitated Hyperliquid. Google later suspended the advertiser linked to the reported campaign, according to reports published after the theft.
Salus ties backend service to Inferno drainer ecosystem
Security firm Salus said an undercover investigation connected the infrastructure used in the theft to the Inferno drainer ecosystem. According to Salus, the service sought customers through the Telegram account @AngelFernoOwner.
Salus said the operator promoted a broad phishing toolkit, including malicious scripts, administrative panels, tools for generating approval commands, one-time contract deployment, automated draining, cross-chain withdrawals, token swaps and fund consolidation. The service also allegedly offered automated revenue sharing so proceeds from successful attacks could be split among participants without manual transfers.
Researchers describe separate roles in the theft
In Salus's account of the Hyperliquid case, the phishing campaign and the draining infrastructure performed different jobs. The phishing group allegedly purchased the sponsored ads, set up the fake Hyperliquid landing page and provided the wallet address meant to receive the proceeds.
After the victim approved the malicious transaction, Salus said the backend system carried out the drain and distributed the funds automatically. The address 0x98b276…13C55 reportedly received 80% of the proceeds, while 0x93b6B2…1d6D1 received 15% and 0x6fE314…B566 received 5%. A fourth address, 0x9bcd…9104a, was identified by Salus as the one that executed the drain.
What the case shows about drainer-as-a-service
The setup described by Salus reflects the drainer-as-a-service model that has become common in crypto phishing. Under that structure, operators do not need to build every part of an attack themselves. Instead, they can rely on ready-made infrastructure for wallet draining and asset movement while focusing on traffic acquisition, fake interfaces and victim targeting.
In this case, Salus said the package on offer covered not only the initial theft mechanism but also later stages such as cross-chain withdrawals, swaps, consolidation and profit distribution. The confirmed next development from the source reporting is Google's suspension of the advertiser tied to the campaign, while the attribution of the broader infrastructure remains based on Salus's investigation.
Source: crypto.news