Google Ad Scam Steals 550k USDC from Hyperliquid User via Automated Theft Infrastructure
A Hyperliquid user fell victim to a phishing scam after clicking on a Google-sponsored ad for a fake version of the decentralized trading platform. The ad directed the user to a counterfeit Hyperliquid website, where they lost approximately 550,000 USDC.
Salus, a blockchain security firm, investigated the incident and connected it to an automated theft infrastructure linked to the Inferno drainer ecosystem. The backend of the service split the stolen funds among addresses tied to the operation.
The investigation found that the phishing group bought the sponsored advertisements, deployed the spoofed Hyperliquid entry point, and supplied the address designated to receive the proceeds. Once the victim approved the malicious transaction and the funds were taken, the infrastructure handled the split automatically.
Salus also linked the infrastructure to approximately $52.74 million in total losses across multiple phishing incidents. The firm traced beyond the Hyperliquid victim and identified groups connected to the infrastructure as responsible for the losses.