Another incident of fund loss has occurred on the decentralized exchange HyperSwap, operating on the HyperEVM blockchain. The victim, who held assets in a common liquidity pool, lost approximately $12,000. The cause was a classic phishing attack carried out through a fake account on social network X. Let's analyze this case in detail to understand the mechanism and learn lessons.
Attack Scheme: From a Fake Post to NFT Theft
A user saw a post in the official HyperSwap account offering a free airdrop. By clicking the link, they landed on a clone site that was visually indistinguishable from the real one. This fake resource required connecting a wallet and confirming a transaction. Believing they were participating in the giveaway, the victim signed permission to manage their deposit, represented as an NFT with a unique number.
The scammers acted methodically: the duplicate account on X differed from the real one by just a couple of characters, and the site itself was an exact copy. Such carelessness cost the user all their funds.
Theft Timeline: Less Than Two Minutes
The active phase of the attack took only two minutes — from 20:21 to 20:23 UTC on June 29, 2026. First, the attacker, using previously obtained access, transferred the NFT token confirming the right to the deposit to their wallet. Key point: this operation was initiated and paid for by the scammer themselves. The victim did not sign anything at that moment — this is the essence of a drainer: access is obtained in advance, and the withdrawal occurs later, without the owner's involvement.
Then, the hacker withdrew all assets from the stolen NFT: approximately 3935 USDC and 116 WHYPE, totaling about $12,100. After that, through the legitimate LI.FI service, all funds were converted to HYPE and sent to the Ethereum network. The address, created shortly before, was used once: it received the assets and almost immediately transferred them further, remaining empty. This is a typical "transit" wallet.
Project Response: Ignoring the Problem
Upon discovering the loss, the victim tried to contact the HyperSwap and Hyperliquid teams to block the fraudulent link. However, no response followed. According to them, the only active communication channel with HyperSwap was Discord, which turned out to be invalid at the time of the request. Attempts to convey information to the Hyperliquid ecosystem team were also unsuccessful.
It is worth noting that the fraudulent address had been active for about a month and was linked to approximately 25 different wallets. This indicates a well-established and streamlined scheme, rather than a random incident.
Precautionary Measures
- Access exchanges and services only through addresses from official sources, not via links from social media posts.
- Carefully check the account name: scammers create duplicates that differ by one or two letters.
- Never confirm operations whose meaning you do not understand — especially granting permissions to manage tokens.
- Regularly check and revoke granted permissions through trusted services, entering their address manually.
- If you suspect theft, immediately revoke all permissions and transfer remaining assets to a new wallet.
My Comment: This incident is a clear example that security in DeFi remains a weak link. Users must be extremely vigilant, and project teams must respond promptly to threats. Ignoring reports of phishing by Hyperliquid and HyperSwap is unacceptable. Ultimately, responsibility for the safety of funds lies with the user, but the ecosystem must create a secure environment, not leave its participants alone against hackers.