BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Markets

Salus links $550,000 Hyperliquid theft to Inferno Drainer phishing network

Blockchain security company Salus stated that the theft of approximately $550,000 in USDC from a Hyperliquid user on August 13 was connected to a professional phishing operation using the Inf

AnonymousCryptoCompass newsroom
August 24, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for markets coverage.

Blockchain security company Salus stated that the theft of approximately $550,000 in USDC from a Hyperliquid user on August 13 was connected to a professional phishing operation using the Inferno Drainer ecosystem.

Fake website targeted victim funds

According to Salus, the attacker set up a counterfeit Hyperliquid site to trick the victim into authorizing a harmful transaction. Following the attack, the stolen assets were distributed to several addresses. Salus mapped the movement of funds, noting that 80% of the stolen amount was sent to one address, 15% to a second, and 5% to a third, while another address was used to complete the initial draining process.

The security team also traced the malicious service to a Telegram account named @AngelFernoOwner, which appeared to promote automated, revenue-sharing features for affiliates. Salus reported that this infrastructure has been linked to an estimated $52.74 million in losses affiliated with multiple high-profile phishing attacks.

Mini dictionary: Inferno Drainer, a phishing-as-a-service network, provides ready-made tools that facilitate automated wallet drains, enabling attackers to siphon cryptocurrencies from victims efficiently using impersonation tactics.

Google has suspended the account responsible for advertising the counterfeit Hyperliquid website. Despite this action, concerns remain regarding the speed at which such malicious advertisements can be detected and removed before affecting users.

Growing risk and operational sophistication

The report highlighted that phishing operations using prebuilt draining services have made it easier for malicious actors to attack victims. Attackers are now able to focus primarily on luring victims, as the technical aspects of asset movement are managed by third-party tools.

For individuals, a legitimate website appearance in major search results no longer ensures safety, as sophisticated phishing can now bypass simple checks and deceive even cautious users.

Salus submitted evidence, wallet addresses considered high risk, and other intelligence to multiple organizations for risk labelling and potential coordinated responses.

Beyond the single Hyperliquid case, Salus has also linked the same phishing infrastructure to incidents involving UXLINK and CoW.fi. The company stated that targeting these broader service networks could disrupt a wider range of phishing operations, rather than simply removing individual fake sites.

IncidentLinked ServiceEstimated LossHyperliquid user attackInferno Drainer$550,000UXLINK phishing caseInferno DrainerNot specifiedCoW.fi phishing caseInferno DrainerNot specifiedTotal associated attacksInferno Drainer$52.74 million

Calls for increased vigilance and coordinated action

The incident has prompted cybersecurity experts to call for greater vigilance from both platforms and individual users. Reviewing site authenticity or relying exclusively on outwardly legitimate search results may not be adequate in safeguarding against such targeted operations.

Salus emphasized that disabling the underlying infrastructure behind recurring phishing schemes could provide more effective protection than simply blocking individual sites as they appear.

Looking ahead, the case illustrates the shifting landscape of crypto security, where the emergence of phishing-as-a-service models makes proactive, industry-wide coordination even more critical.

The post Salus links $550,000 Hyperliquid theft to Inferno Drainer phishing network appeared first on COINTURK NEWS.