Fake Hyperliquid Website Causes User Loss of 550,000 USDC Through Google Ads
On August 13, 2026, a fake Hyperliquid website attracted users through Google sponsored ads, resulting in a victim losing approximately 550,000 USDC.
Security agency Salus confirmed after cross-verifying subsequent fund flows that the case utilized a specialized cryptocurrency theft service infrastructure highly associated with the Inferno system. The related services had previously solicited clients through Telegram accounts. The phishing gang was responsible for purchasing ads, deploying counterfeit entry points, and providing final collection addresses. After successful thefts, the backend automatically completed fund splitting.
Further tracing revealed that the total amount involved with the related gang was approximately 52.74 million USD, and it was linked to several well-known phishing incidents, including the UXLINK second authorization phishing in September 2025, the CoW.fi domain hijacking in April 2026, and the fake DApp/airdrop authorization phishing in July 2026. Relevant evidence, risk addresses, and associated clues have been submitted to the relevant authorities for risk marking and collaborative disposal.
From a market mechanism perspective, the incident has driven an escalation in phishing risks associated with search ads. The cross-chain and aggregation paths of funds flowing to stolen assets benefit specialized cryptocurrency theft infrastructure operators, while users and platforms bear the pressure of trust. The abuse of Google ads highlights the ongoing necessity for entry protection and domain verification.
Source: Public Information
ABAB AI Insight
This case directly links Google sponsored ads with specialized cryptocurrency theft infrastructure, indicating that phishing has shifted from independent gangs to a service-oriented division of labor: front-end responsibilities for ad traffic and counterfeit entry points, while the back-end automates fund splitting and transfer. The total scale of related historical cases reaches tens of millions of dollars, indicating that the same infrastructure has been reused multiple times.
In terms of capital pathways, the theft service incentivizes front-end gangs through a profit-sharing mechanism, forming a scalable black industrial chain. This is an upgraded version of previous authorization phishing and domain hijacking incidents, with the key being that advertising platforms have become new traffic entry points. We are currently in a phase of collaborative strikes against search ads and on-chain cryptocurrency theft infrastructure.
This is analogous to other cryptocurrency phishing cases that have attracted traffic through legitimate advertising channels.
Essentially, this reflects regulatory changes. The mechanism is that legitimate advertising systems are used to distribute counterfeit entry points, reducing customer acquisition costs, while back-end services lower technical barriers, significantly enhancing the scale and reuse efficiency of attacks.
ABAB News · Cognitive Laws
- Once the advertising entry is abused, the cost of counterfeiting will significantly decrease.
- The profit-sharing mechanism of theft services sustains the industrial chain better than single attacks.
- The true amplifier of user losses is reusable infrastructure rather than single scripts.