Crypto news report · source clearly identified

Fake Hyperliquid Google ad linked to Inferno drainer steals USDC

A Hyperliquid user has lost about 550,000 USDC after a Google sponsored advertisement directed the victim to a fake version of the decentralized trading platform, with investigators linking the theft infrastructure to the Inferno drainer ecosystem.

A user of the decentralized trading platform Hyperliquid lost roughly 550,000 USDC after clicking a Google‑sponsored advertisement that led to a counterfeit Hyperliquid website. Security firm Salus traced the theft to a professional drainer‑as‑a‑service network associated with the Inferno ecosystem.

Phishing attack mechanics

The fraudulent ad appeared in paid Google search results on August 13. The victim was directed to a spoofed Hyperliquid entry point, approved a malicious transaction, and the funds were automatically routed through a backend infrastructure that split the proceeds among several addresses.

Automated revenue sharing

  • 80% of the stolen USDC was sent to address 0x98b276…13C55
  • 15% went to address 0x93b6B2…1d6D1
  • 5% was transferred to address 0x6fE314…B566
  • A fourth address 0x9bcd…9104a executed the final drain

Infrastructure and service model

Salus identified a Telegram account (@AngelFernoOwner) used to market a suite of tools, including malicious scripts, approval‑command generators, one‑time contract deployment, automated draining, cross‑chain withdrawals, token swaps, and fund consolidation. The service offered “automated revenue sharing,” allowing participants to receive a portion of proceeds without manual transfers.

Broader impact of the Inferno drainer

Beyond the Hyperliquid incident, Salus linked the same infrastructure to approximately $52.74 million in losses across multiple phishing cases, including:

  • A September 2025 UXLINK phishing attack that moved roughly 542 million UXLINK tokens (over $43 million at the time).
  • An April 15, 2026 CoW.fi domain hijack that resulted in a loss of about 316,000 USDC.
  • A July 9, 2026 fake DApp/airdrop that stole 999,999 USDT.

Google later suspended the advertiser linked to the Hyperliquid campaign.

Response and mitigation

Salus submitted evidence, high‑risk address data, and intelligence to relevant authorities for risk labeling and coordinated action. The case highlights the growing threat of drainer‑as‑a‑service platforms that separate phishing front‑ends from the backend wallet‑draining infrastructure.

Source & attribution

News Source

Publisher
crypto.news
Original date
August 24, 2026, 8:15 AM
Original headline
Fake Hyperliquid Google ad linked to Inferno drainer steals USDC
View original report ↗