Inferno Drainer Ecosystem Tied to Multi-Million Dollar Phishing Attacks
A fake Google ad for Hyperliquid led to a phishing attack that resulted in the loss of approximately $550,000 worth of USDC. The incident occurred on August 13 and was linked to the Inferno drainer ecosystem by blockchain security firm Salus.
The firm's investigation found that the phishing group bought sponsored ads, deployed the spoofed Hyperliquid entry point, and supplied the address designated to receive the proceeds. Once the victim approved the malicious transaction, the infrastructure handled the split automatically.
Salus attributed separate roles to the phishing group and the backend service, which offered 'automated revenue sharing' for dividing proceeds among participants without manual transfers.
The firm linked the infrastructure to approximately $52.74 million in losses across multiple phishing incidents, including a September 2025 UXLINK exploit and an April 15, 2026 CoW.fi incident.