BITWU.ETH 🔆
BITWU.ETH 🔆|Aug 25, 2026 03:28
I just can’t wrap my head around this—this guy has 550K USDT, yet he made such a rookie mistake by Googling a URL! Web3 phishing has become highly industrialized these days. Salus continued tracking and believes the attack was carried out using a professional Drainer-as-a-Service closely tied to the Inferno ecosystem. Here’s roughly how the attack chain works: 1⃣ The attacker buys Google search ads related to “Hyperliquid,” making malicious links appear at the top of search results where users are more likely to trust them. 2⃣ The fake page mimics Hyperliquid’s branding, interface, and transaction portal, tricking users into thinking they’re on the official platform. 3⃣ The victim signs a malicious authorization that allows the attacker to transfer their tokens. 4⃣ The Inferno Drainer backend automatically handles the theft, cross-chain transfers, token swaps, aggregation, and profit-sharing—no need for the attacker to manually process each transaction. On-chain, you can see three transactions totaling approximately 440,015, 82,503, and 27,501 USDC, which perfectly match an 80% / 15% / 5% profit-sharing split. These types of attacks are only going to increase. A mature Drainer infrastructure can simultaneously support dozens or even hundreds of phishing groups: Tech teams handle the product, marketing teams handle ad buys, black-market groups handle victim acquisition, and smart contracts handle settlement. So the only advice is: Always double-check every operation involving funds. Always stay hyper-vigilant about authorization actions like approve, permit, and setApprovalForAll.
+5
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads