A user lost about 550,000 USDC after clicking a Google sponsored ad that led to a fake Hyperliquid website. According to Odaily, the scheme used professional theft-service infrastructure linked to the Inferno network, with Telegram accounts recruiting clients and offering malicious scripts, automated theft, cross-chain withdrawals, and automatic fund splitting. In this case, the phishing group bought ads, set up a counterfeit entry page, and provided the final receiving address, while the backend automatically split the stolen funds after the theft.
