A Hyperliquid user lost approximately 550,000 USDC after clicking a Google-sponsored advertisement that led to a counterfeit version of the decentralized trading platform. Blockchain security firm Salus reported the theft in an Aug. 24 post on X, saying the incident occurred on Aug. 13 and was connected to professional drainer-as-a-service infrastructure linked to the Inferno drainer ecosystem.
Salus said its investigation traced the stolen funds and reviewed the backend infrastructure behind the fake page. The phishing group purchased sponsored ads, deployed the spoofed Hyperliquid entry point, and supplied the address designated to receive proceeds. After the victim approved the malicious transaction, the infrastructure automatically split the funds: address 0x98b276…13C55 received 80%, 0x93b6B2…1d6D1 received 15%, and 0x6fE314…B566 received 5%, while a fourth address executed the drain.
The stolen amount was approximately 550,019 USDC, moved in three transfers of about 440,015 USDC, 82,503 USDC, and 27,501 USDC to attacker-controlled addresses. Google later suspended the advertiser linked to the campaign.
Salus said the drainer service advertised its tools through the Telegram account @AngelFernoOwner, offering malicious scripts, administrative panels, approval-command generation, one-time contract deployment, automated draining, cross-chain withdrawals, token swaps, fund consolidation, and automated revenue sharing. Groups connected to the infrastructure were linked to roughly $52.74 million in total losses across multiple phishing incidents, including the September 2025 UXLINK exploit and an April 15, 2026 CoW.fi domain hijacking that caused a victim to lose about 316,000 USDC. A July 9 incident involving a malicious approval drained 999,999 USDT.
Salus said evidence, high-risk addresses, and related intelligence had been formally submitted to relevant organizations for risk labeling and coordinated action.