Salus links the $550,000 theft of Hyperliquid to the Inferno Drainer phishing network
Blockchain security company Salus pointed out that the theft of approximately $550,000 USDC by a Hyperliquid user on August 13 was related to a professional phishing operation using the Inferno Drainer ecosystem.
Fake websites target user funds
According to Salus, the attacker set up a fake Hyperliquid website to trick victims into authorizing a harmful transaction. After the attack, stolen assets were dispersed and transferred to multiple addresses. Salus tracked the money flow and found that 80% of the stolen money was sent to one address, 15% to a second address, and 5% to a third address, while another address was used to complete the initial money theft process.
The security team also traced the malicious service to a Telegram account called @AngelFernoOwner, which appeared to promote automated revenue sharing for partners. Salus reported that this infrastructure has been linked to multiple high-profile phishing attacks, causing approximately $52.74 million in damage.
Mini Dictionary: Inferno Drainer is a "phishing as a service" network that provides ready-made tools to automatically steal wallet funds, allowing attackers to efficiently steal cryptocurrency from victims through impersonation.
Google has suspended accounts that advertise fake Hyperliquid websites. Despite this measure, people are still concerned about whether such malicious advertisements can be discovered and removed in a timely manner before being clicked by users.
Increasingly escalating risks and operational methods
The report emphasizes that phishing operations using pre-configured stolen services make it easier for malicious actors to attack victims. Attackers can now focus mainly on luring victims, while the technical aspects of asset transfer are handled by third-party tools.
For individual users, seeing the appearance of legitimate websites in mainstream search results is no longer guaranteed security, as sophisticated phishing techniques can now bypass simple inspections and even deceive vigilant users.
Salus submitted evidence, wallet addresses identified as high-risk, and other intelligence to multiple organizations for risk tagging and potential coordinated responses.
In addition to the single Hyperliquid case, Salus also linked the same phishing infrastructure to UXLINK and www.example.com. CoW.fi The company said a crackdown on these broader service networks could be more effective in curbing a series of phishing actions than just removing individual fake websites.
Call for increased vigilance and enhanced coordinated action
The incident prompted cybersecurity experts to call for greater vigilance on both platforms and individual users. Simply checking website authenticity or relying entirely on seemingly legitimate search results may not be enough to prevent such targeted attacks.
Salus emphasized that disabling the underlying infrastructure behind recurring phishing schemes provides more effective protection than simply blocking a single fake website when it appears.
Looking ahead, this case demonstrates the transformation of the cryptocurrency security landscape, with the emergence of the phishing as a service model making proactive, industry-wide coordination even more critical.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following