The issue of security on decentralized platforms is once again being raised in the crypto community. This time, a user fell victim, losing approximately $12,000 on the HyperSwap exchange, which operates on the Hyperliquid blockchain (HyperEVM layer). The incident occurred due to a classic phishing attack, but with alarming consequences: the victim claims the project team ignored his warnings.
An analysis of blockchain data, conducted by me, shows that the attack was carefully planned. The attackers created a fake account on social network X that is visually indistinguishable from the official HyperSwap profile. The difference is just a couple of characters in the name. It was through this fake account that the malicious link, leading to a clone website, was distributed.
How the scheme works: from link to theft in two minutes
The victim, a liquidity provider in the HyperSwap pool, clicked on a link from a post he believed was an official announcement about a token airdrop. On the clone website, he connected his wallet and confirmed a transaction, thinking he was checking his eligibility for free coins. In reality, he granted the scammers permission (approve) to manage his investment, represented as an NFT with a unique number.
Key point: the attackers were not in a hurry. The permission was obtained in advance. The theft itself took only two minutes — from 20:21 to 20:23 UTC on June 29, 2026. At that moment, the fraudulent address (marked by the security service HashDit as Fake_Phishing3746335) transferred the NFT with the victim's investment to its wallet. The victim did not sign anything at that moment — the hacker initiated and paid for the entire operation. This is the essence of a drainer: access is obtained in advance, and the withdrawal of funds occurs later, without the owner's involvement.
Assets were extracted from the NFT: approximately 3935 USDC and 116 WHYPE, totaling around $12,100. Then, using the legitimate bridge and exchange service LI.FI, the attacker converted everything into HYPE and withdrew about $12,300 from the HyperEVM network to the Ethereum network, to a one-time "transit" wallet, which was immediately emptied.
Project reaction: a wall of silence
The most alarming part of this story is the reaction of the Hyperliquid and HyperSwap teams. The victim claims he tried to warn the project about the fraudulent link, which had been in the comments since June 26. However, his appeals via Discord and GitHub were ignored. The Hyperliquid team redirected him back to HyperSwap, whose communication channel was inactive at the time.
The victim even suggested that HyperSwap employees might be involved in the theft or deliberately covering it up. There is no direct evidence of this, but the very fact that the project ignored the problem raises serious questions about its approach to user security.
This incident is not a coincidence, but a well-established scheme. The scammer's address was active for about a month and was linked to approximately 25 different wallets. It is clear that we are dealing with an organized group targeting users of the Hyperliquid ecosystem.
Conclusions from Cryptalist analyst
This case is a harsh reminder that in the decentralized world, security is a personal responsibility. Platforms, especially young ones, often lack the resources to respond quickly to threats. Users need to develop ironclad rules: never click on links from social media, verify contract addresses, and regularly revoke suspicious permissions through specialized services. Until the community begins to massively demand that projects implement early warning and rapid response systems, such thefts will continue.