In the world of DeFi, where decentralization is a key advantage, attackers are finding new vulnerabilities by exploiting human carelessness. A recent incident on the decentralized exchange HyperSwap, operating on the HyperEVM layer of the Hyperliquid ecosystem, clearly demonstrates how a classic phishing scheme can lead to the loss of significant funds. The victim lost approximately $12,000, and this case reveals serious security gaps not only at the user level but also at the project's response level.
Anatomy of the Attack: From a Fake Post to an Empty Wallet
It all started with a seemingly harmless post on social network X. A user, who held assets in the HyperSwap liquidity pool, came across an announcement about a token distribution (airdrop) from what appeared to be the exchange's official account. Clicking on the link, they landed on a website visually indistinguishable from the real one. However, behind this was not an airdrop, but a sophisticated drainer—a tool for stealing funds from crypto wallets.
The key element of the attack was impersonation. The scammers' account was nearly identical to the official HyperSwap account, differing by just a couple of characters. The user, not noticing the trick, connected their wallet to the fake website and confirmed a transaction, believing they were simply checking their eligibility for free tokens. In reality, they granted the attacker permission to manage their investment—an NFT confirming their share in the liquidity pool.
Instant Theft and Covering Tracks
The theft itself occurred within two minutes. As soon as permission was granted, the fraudulent address, flagged by security services as Fake_Phishing3746335, used the access to transfer the victim's NFT with their investment to its own wallet. It is important to note that the victim did not sign anything at that moment—this is the danger of drainers: access is tricked out in advance, and the withdrawal of funds happens later, without the owner's involvement.
Next, the attacker extracted all the liquid funds from the NFT: approximately 3,935 USDC and 116 WHYPE, totaling around $12,100. To withdraw the funds, they used the legitimate cross-chain service LI.FI, converting everything into HYPE and sending about $12,300 to the Ethereum network to a one-time "transit" wallet. Using a legitimate service complicates tracking and creates a false impression that the infrastructure itself is to blame for the theft.
Project Response: Deafness or Complicity?
The most alarming aspect of this incident is the reaction from the Hyperliquid and HyperSwap teams. Upon discovering the loss, the victim tried to contact the Hyperliquid team via Discord to report the fraudulent link, which was still visible in the comments. However, their requests were ignored, and the only active communication channel with HyperSwap turned out to be non-functional. The Hyperliquid team redirected them back to HyperSwap, effectively washing their hands of the problem.
This raises serious questions about ecosystem responsibility. Hyperliquid provides the infrastructure but does not control the applications running on it. However, when fraudulent activity thrives in plain sight and the team fails to respond to signals, it sets a dangerous precedent. The victim reasonably suspected that HyperSwap employees might be involved in the theft or, at the very least, were deliberately covering it up.
Analyst Conclusions
This case is not just a story of one loss. It is a wake-up call for the entire Hyperliquid ecosystem. Until the project team takes responsibility for user safety, at least at the level of moderation and rapid threat response, such "blind spots" will remain a goldmine for scammers. Users, for their part, should remember: verify wallet addresses and account names letter by letter, do not confirm suspicious transactions, and most importantly, do not trust promises of free giveaways. In the world of DeFi, your security is your personal responsibility, and relying on anyone else's vigilance, unfortunately, is not an option.