On August 13, 2026, a fake Hyperliquid website promoted through Google sponsored ads caused a victim to lose 550k USDC.
After cross-checking the subsequent fund flows, we confirmed that the case involved professional drainer-as-a-service infrastructure closely linked to the Inferno ecosystem.
Our undercover investigation found that the service had solicited clients through the Telegram account
@AngelFernoOwner, claiming to provide malicious scripts, admin panels, approval-command generation, one-time contract deployment, automated draining, cross-chain withdrawals, token swaps and consolidation, and automated revenue sharing.
In this case, the phishing group purchased the ads, deployed the spoofed website, and supplied the final receiving address. Once the theft succeeded, the backend automatically split the proceeds:
- 0x6fE314…B566 received 5%
- 0x93b6B2…1d6D1 received 15%
- 0x98b276…13C55 received 80%
- 0x9bcd…9104a executed the drain
Further tracing revealed that the groups linked to this infrastructure were involved in approximately $52.74 million in total losses, including several major phishing incidents:
On September 23, 2025, the original UXLINK
@UXLINKofficial attacker fell victim to a secondary approval-phishing attack involving approximately 542 million UXLINK tokens, as reported by
@evilcos:
On April 15, 2026, the official domain was hijacked, with one associated victim losing approximately 316,000 USDC, as reported by
@GoPlusSecurity:
On July 9, 2026, an approval-phishing attack involving a suspected fake DApp or fake airdrop resulted in the theft of 999,999 USDT, as reported by
@realScamSniffer:
All supporting evidence, high-risk addresses, and related intelligence have been formally submitted to the relevant organizations for risk labeling and coordinated action.