The August 13 incident involved a counterfeit website that mirrored the authentic Hyperliquid interface. After the victim interacted with the malicious site and authorized a transaction, the infrastructure automatically executed the theft, splitting the stolen funds among multiple attacker-controlled addresses. Blockchain analysis revealed that 80% of the proceeds were routed to one specific wallet, with smaller portions distributed to secondary accounts.
Salus identified this operation as part of a broader drainer-as-a-service model, where developers provide phishing tools—including malicious scripts and automated contract deployment—to affiliates. These operators focus exclusively on purchasing search engine advertisements and managing victim engagement. The firm’s investigation into the Telegram account @AngelFernoOwner uncovered a suite of tools designed for cross-chain withdrawals, token swaps, and asset consolidation, all operating under an automated revenue-sharing scheme.

Comments (0)
No comments yet. Be the first!