A single click on the top search result on Google led to the loss of half a million dollars. A user of the Hyperliquid platform lost approximately 550,000 USDC on August 13, 2026, after unwittingly visiting a fake site via a paid Google advertisement link. Blockchain security firm Salus, which investigated the fund flow, discovered a pattern much larger than standard phishing. The fraudulent infrastructure was found to be directly connected to the Inferno ecosystem, an organized drainer-as-a-service operation that rents out crypto theft tools to anyone willing to share the stolen proceeds.
Inferno does not operate like a lone actor working independently, but rather resembles a software company. The service offers a complete hacking package, ranging from malicious scripts and providing an admin panel to generating target wallet approval commands. They also facilitate the deployment of single-use contracts. Once the victim’s wallet is connected, Inferno’s system immediately drains the assets, transfers funds across various networks, swaps tokens, and consolidates all proceeds in a single location without further manual instructions.
Automated Revenue Sharing via Smart Contracts
One of the features offered by Inferno is automated revenue sharing - the looted assets are immediately split and distributed to the various parties involved. In the case of the Hyperliquid user’s lost funds, the drained total of 550,019 USDC was instantly split into three transfers. Wallet address 0x98b276 received the largest share of approximately 440,015 USDC, equivalent to 80% of the total funds. The rest flowed to wallet 0x93b6B2, receiving 82,503 USDC or a 15% share, and to wallet 0x6fE314, receiving 27.501 USDC or a 5% share. This scheme demonstrates a clear commission sharing structure between the Inferno infrastructure provider and their clients who ran the advertisements.
Although Google subsequently suspended the advertiser account running the fake Hyperliquid ad campaign, this reactive measure could not recover the victim’s funds. For the Inferno syndicate itself, the 550,000 USDC is just a small fraction of their overall operations, which continue to claim victims.
A Long Trail of $52 Million in Losses
The Inferno drainer service has surfaced repeatedly in major hacking incidents. Salus noted that their infrastructure was behind the theft of 55 million DAI from a Coinbase user in August 2024. They are also linked to the $43 million exploit of the UXLINK protocol in September 2025, as well as the hijack of the CoW.fi domain in April 2026, which managed to drain approximately 316,000 USDC. In total, Salus calculates that losses connected to Inferno’s infrastructure amount to approximately $52.74 million across various phishing incidents.
As a mitigation step, Salus has now submitted all evidence, list of high-risk addresses, and intelligence to various relevant organizations so that these hacker addresses can be labeled for their risk. The emergence of ready-to-use services like Inferno lowers the technical barrier required to steal crypto, turning hacking into a subscription-based business model. As long as search engine ads remain vulnerable to malicious links, the user’s final defense is to double-check every character of the URL before approving any transaction.
Reported from crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




