User loses about 550,000 USDC through fake Hyperliquid site

A Hyperliquid user lost about 550,000 USDC on August 13 after a Google sponsored advertisement led to a counterfeit version of the decentralized trading platform. Blockchain security firm Salus said the attack used professional drainer-as-a-service infrastructure linked to the Inferno ecosystem, marketed through Telegram with tools for malicious scripts, approval commands, automated draining, cross-chain withdrawals, swaps, consolidation and automated revenue sharing. The phishing operators bought the ads, deployed the spoofed site and supplied the collection address, while the backend automatically split proceeds among designated addresses after a fourth address executed the drain. Earlier fund-flow reporting showed roughly 550,019 USDC moved in three transfers, and Google later suspended the linked advertiser. Salus connected groups using the infrastructure to about $52.74 million in losses across incidents including UXLINK, CoW.fi and a fake dapp or airdrop, and said evidence and high-risk addresses had been submitted for risk labeling and coordinated action.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.