EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Salus linked the $550,000 Hyperliquid theft to Inferno Drainer phishing network

2026-08-25 00:23:55
Bookmark

Salus links the $550,000 theft of Hyperliquid to the Inferno Drainer phishing network

Blockchain security company Salus pointed out that the theft of approximately $550,000 USDC by a Hyperliquid user on August 13 was related to a professional phishing operation using the Inferno Drainer ecosystem.

Fake websites target user funds

According to Salus, the attacker set up a fake Hyperliquid website to trick victims into authorizing a harmful transaction. After the attack, stolen assets were dispersed and transferred to multiple addresses. Salus tracked the money flow and found that 80% of the stolen money was sent to one address, 15% to a second address, and 5% to a third address, while another address was used to complete the initial money theft process.

The security team also traced the malicious service to a Telegram account called @AngelFernoOwner, which appeared to promote automated revenue sharing for partners. Salus reported that this infrastructure has been linked to multiple high-profile phishing attacks, causing approximately $52.74 million in damage.

Mini Dictionary: Inferno Drainer is a "phishing as a service" network that provides ready-made tools to automatically steal wallet funds, allowing attackers to efficiently steal cryptocurrency from victims through impersonation.

Google has suspended accounts that advertise fake Hyperliquid websites. Despite this measure, people are still concerned about whether such malicious advertisements can be discovered and removed in a timely manner before being clicked by users.

Increasingly escalating risks and operational methods

The report emphasizes that phishing operations using pre-configured stolen services make it easier for malicious actors to attack victims. Attackers can now focus mainly on luring victims, while the technical aspects of asset transfer are handled by third-party tools.

For individual users, seeing the appearance of legitimate websites in mainstream search results is no longer guaranteed security, as sophisticated phishing techniques can now bypass simple inspections and even deceive vigilant users.

Salus submitted evidence, wallet addresses identified as high-risk, and other intelligence to multiple organizations for risk tagging and potential coordinated responses.

In addition to the single Hyperliquid case, Salus also linked the same phishing infrastructure to UXLINK and www.example.com. CoW.fi The company said a crackdown on these broader service networks could be more effective in curbing a series of phishing actions than just removing individual fake websites.

Incident Related Services Estimated Damage Hyperliquid User Attack Inferno Drainer US$550,000 UXLINK Fishing Incident Inferno Drainer Unstated CoW.fi phishing incident Inferno Drainer Unstated Total damage from linked attacks Inferno Drainer US$52.74 million

Call for increased vigilance and enhanced coordinated action

The incident prompted cybersecurity experts to call for greater vigilance on both platforms and individual users. Simply checking website authenticity or relying entirely on seemingly legitimate search results may not be enough to prevent such targeted attacks.

Salus emphasized that disabling the underlying infrastructure behind recurring phishing schemes provides more effective protection than simply blocking a single fake website when it appears.

Looking ahead, this case demonstrates the transformation of the cryptocurrency security landscape, with the emergence of the phishing as a service model making proactive, industry-wide coordination even more critical.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP