A user lost approximately 550,000 USDC after clicking on a sponsored Google ad that led to a counterfeit Hyperliquid website. The case involved a cryptocurrency theft service infrastructure associated with the Inferno system, which recruited clients through Telegram accounts and offered malicious scripts, automated theft, cross-chain withdrawals, and automatic profit distribution features. The phishing gang was responsible for purchasing ads, deploying counterfeit entry points, and providing final collection addresses. Once the theft was successful, the backend automatically completed the fund splitting. The related gang has been involved in cases totaling approximately 52.74 million USD and is linked to multiple significant phishing incidents, including a secondary authorization phishing attack on the original attacker of UXLINK on September 23, 2025, resulting in a loss of about 542 million UXLINK; the hijacking of the official domain of CoW.fi on April 15, 2026, with a loss of 316,000 USDC; and a phishing attack involving fake DApps/fake airdrop authorizations that stole around 1 million USDT on July 9, 2026. Salus stated that the relevant evidence and high-risk addresses have been submitted to the appropriate authorities for action.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























