Fake Hyperliquid site promoted through Google ads linked to $52.74 million in phishing losses

Fake Hyperliquid site promoted through Google ads linked to $52.74 million in phishing losses

N
News Editor
2026-08-24 08:40:21
A fake Hyperliquid website promoted through Google sponsored ads led to the theft of about 550,000 USDC from one victim on Aug. 13, according to security firm Salus. After tracing the flow of funds, investigators said the operation was tied to professional Drain-as-a-Service, or DaaS, infrastructure closely associated with the Inferno ecosystem. The toolkit identified in the probe included malicious scripts, admin panels, approval-command generation, one-time contract deployment, automated wallet draining, cross-chain cash-outs, token swaps and fund aggregation, along with an automated revenue-sharing system. In this case, the phishing group was responsible for buying Google ads, deploying the spoofed website and supplying the final receiving address. Once funds were stolen, the backend automatically split the proceeds based on preset ratios. Investigators also found that multiple groups linked to the same infrastructure had taken part in several large phishing attacks before, with combined losses reaching about $52.74 million. The incident highlights the risk of fake crypto platforms being pushed through search-engine advertising.

Security firm Salus said a fake Hyperliquid website was promoted through Google sponsored ads and caused one victim to lose about 550,000 USDC on Aug. 13, according to a BlockBeats report published Aug. 24.

Fund tracing pointed to professional DaaS infrastructure

After tracing the movement of funds, investigators confirmed that the incident involved professional Drain-as-a-Service, or DaaS, infrastructure closely tied to the Inferno ecosystem.

The investigation said the service offered a full set of tools, including malicious scripts, management panels, approval-command generation, one-time contract deployment, automated token theft, cross-chain withdrawals, token swaps and fund aggregation. It also supported automated profit sharing.

Phishing operators handled ad purchases and the spoofed site

In this attack, the phishing group bought Google ads, deployed the fake website and provided the final receiving address. After a successful theft, the backend automatically split the stolen funds based on preset ratios.

Further fund tracing showed that several groups connected to the same infrastructure had also taken part in multiple large-scale phishing attacks before, with cumulative losses reaching about $52.74 million.

Search ads remain a channel for fake crypto platforms

The case highlights the risk of phishing attacks that use search-engine advertising to promote fake crypto platforms. Users visiting trading platforms should verify website domains and ad sources carefully to avoid losses caused by spoofed pages.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
10

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.