The Hyperliquid ecosystem, despite its popularity, remains vulnerable to classic phishing schemes. This time, a user of the decentralized exchange HyperSwap, operating on the HyperEVM layer, became a victim, losing approximately $12,000. The incident occurred due to the impersonation of the project's official account on the social network X (Twitter).

Attack Scheme: A Doppelgänger Instead of the Original

The victim held assets in a HyperSwap liquidity pool, where their share was confirmed by a unique NFT. On their X feed, they came across a post, supposedly from the exchange's official account, offering a free airdrop. By clicking the link, the user landed on a clone website that was visually indistinguishable from the real one. However, the post was published not from the real account, but from a doppelgänger account differing by just a couple of characters. The scammers' calculation was simple: a moment of inattention costs all the funds.

The Moment of Theft: Less Than Two Minutes

On the fake website, the victim connected their wallet and confirmed the transaction, thinking they were checking their eligibility for tokens. In reality, they granted the attacker permission to manage their deposit. Externally, the transaction was no different from normal actions on legitimate services, so the trick went unnoticed until the funds were debited.

The active phase of the theft occurred between 20:21 and 20:23 UTC on June 29, 2026. The fraudulent address, flagged by the security service HashDit as Fake_Phishing3746335, used the previously obtained access and transferred the NFT with its attached assets to its own wallet. Importantly: this operation was initiated by the scammer themselves, who also paid the fee — the victim did not sign anything at the moment of the theft. This is the essence of a drainer: access is tricked out of the victim in advance, and the withdrawal is carried out later, without the owner's involvement.

How They Covered Their Tracks

From the NFT, the attacker extracted approximately 3935 USDC and 116 WHYPE (totaling ~$12,100). Then, through the legitimate service LI.FI, they converted everything into HYPE and withdrew about $12,300 from the HyperEVM network to Ethereum. The funds arrived at an address created shortly before and were almost immediately sent further, leaving the wallet empty. Such a one-time "transit" wallet is a typical element in the chain of stolen asset withdrawal.

Notably, the scammer used not a hacking tool but an ordinary, legitimate cross-chain transfer service for the withdrawal. This complicates tracking and creates a false impression for the victim that the service or the exchange itself is to blame.

Project Reaction and Lessons Learned

Upon discovering the loss, the user tried to contact the HyperSwap team to have the link to the fraudulent resource removed, but it had been active since June 26. According to them, the only communication channel with HyperSwap was Discord, which, at the time of writing this article, turned out to be invalid. The attempt to report the issue to the Hyperliquid ecosystem team was also unsuccessful. The victim suggested that HyperSwap employees might be involved in the theft or deliberately concealing it.

Expert Opinion

This case is a stark example that security in DeFi depends not only on smart contract code but also on user vigilance and support responsiveness. Scammers have mastered social engineering, creating convincing clones. I recommend always accessing exchanges only through addresses from official sources, checking account names letter by letter, and never confirming transactions whose purpose is unclear. Regularly checking and revoking granted permissions through verified services is a mandatory procedure for anyone holding assets in liquidity pools.