In the decentralized financial environment, where the responsibility for asset security lies entirely with the user, a lapse in attention can be very costly. Another confirmation of this is the incident on the HyperSwap platform, operating on the HyperEVM network. A user lost approximately $12,000, falling victim to a classic phishing attack, which, unfortunately, remains one of the most effective in the cryptocurrency space.

Analysis of the transactions and provided data allowed for a full reconstruction of the events. This was not a protocol hack or a smart contract vulnerability—it was calculated social engineering exploiting the "blind spot" of security: the human factor.

How It Happened: A Step-by-Step Reconstruction of the Attack

The victim held assets in a HyperSwap liquidity pool, where the right to a share is confirmed by a unique NFT. It all started on social network X. The user saw a post that was visually indistinguishable from an official HyperSwap project announcement. It offered a chance to check eligibility for a free airdrop—a classic lure.

The key element of the deception was account spoofing. The attackers created a duplicate account, whose name differed from the official one by just a couple of characters. The same fate befell the link in the post: it led not to the real HyperSwap website, but to its phishing clone, which looked absolutely identical.

Without noticing the substitution, the user clicked the link, connected their wallet, and confirmed the transaction. Outwardly, it appeared to be a routine verification operation, but in reality, they signed an approval (approve) granting control over their NFT token representing the pool share. This moment—granting permission—is the point of no return.

Instant Theft: Less Than Two Minutes

The active phase of the theft occurred on June 29, 2026, between 20:21 and 20:23 UTC. The fraudulent address, flagged by the security service HashDit as Fake_Phishing3746335, using the obtained access, transferred the victim's NFT to its own wallet. It is important to note: this transaction was initiated and paid for by the attacker themselves; the victim did not sign anything at that moment. This is the essence of a "drainer"—access is obtained in advance, and the withdrawal of funds happens later, without the owner's involvement.

After that, the hacker "extracted" all the deposited assets from the stolen NFT: approximately 3,935 USDC and 116 WHYPE, totaling about $12,100. Then, using the legitimate cross-chain service LI.FI, they converted everything into HYPE and withdrew approximately $12,300 from the HyperEVM network to the Ethereum network. Using a legitimate service to cover tracks is a common technique that complicates tracking and creates the false impression that the bridge protocol itself is to blame for the theft.

Project Response: Ignoring the Problem

Upon discovering the loss, the victim tried to contact the HyperSwap and Hyperliquid teams to report the phishing link. However, their attempts were unsuccessful. The link to the fraudulent resource had been active in messages since June 26. According to the user, the only active communication channel with HyperSwap was Discord, which turned out to be invalid at the time of the request. Contacting Hyperliquid support was also ignored—the ecosystem team redirected them back to the HyperSwap developers, creating a closed loop.

The situation raises serious questions about the security culture within the ecosystem. The fraudulent address was active for about a month and was linked to approximately 25 different wallets, indicating a well-established, streamlined scheme rather than a random incident.

Analyst's Opinion

This case is a vivid illustration that in DeFi, security begins not with code audits, but with user behavior. As long as such simple yet effective phishing schemes continue to work, and projects ignore signals about the problem, we will continue to see new victims. The Hyperliquid ecosystem urgently needs to implement proactive protection and monitoring measures; otherwise, reputational risks may outweigh technological advantages.