The Hyperliquid ecosystem, despite its popularity, proves vulnerable to classic phishing attacks. One user lost approximately $12,000 on the decentralized exchange HyperSwap, operating on the HyperEVM network. The funds were stolen after clicking a fraudulent link on social network X. This is not an isolated incident but a well-established scheme that can affect any inattentive trader.

How It Happened

The victim held assets in the HyperSwap liquidity pool, where the share right is confirmed by a unique NFT. On the official HyperSwap account on X, they saw a post with a link to a website that supposedly offered a free airdrop. In reality, the link led to a drainer—a tool for stealing funds from a crypto wallet.

The scammers created a duplicate account, whose name differed from the real one by just a couple of characters. The user did not notice the substitution and went to the fake website, which visually copied the official resource. There, they connected their wallet and confirmed the transaction, thinking they were checking eligibility for free tokens. In fact, they granted the attackers permission to manage their investment. Externally, the transaction was no different from normal actions on legitimate services, so the trick went unnoticed.

The Theft in Two Minutes

The active phase of the attack occurred between 20:21 and 20:23 UTC on June 29, 2026. The fraudulent address, labeled by the HyperEVMscan explorer as Fake_Phishing3746335, used previously obtained access and transferred the NFT with the investment to its own wallet. Notably, the transaction itself was initiated by the attacker, who also paid the fee—the victim did not sign anything at that moment. This is the essence of the drainer: access is obtained in advance, and the withdrawal is carried out later, without the owner's involvement.

The scammer then extracted the invested coins from the NFT: approximately 3,935 USDC and 116 WHYPE, totaling around $12,100. Through the legitimate exchange service LI.FI, they converted all stolen assets into HYPE and sent about $12,300 from the HyperEVM network to the Ethereum network.

Traces and Reaction

On the Ethereum network, the funds arrived at a one-time "transit" wallet, which was immediately emptied. This is a typical element of the money laundering chain. According to the explorer, the fraudulent address was active for about a month and linked to approximately 25 different wallets, indicating a well-established, streamlined scheme rather than a random incident.

The victim tried to contact the Hyperliquid team via Discord to report the issue and request the removal of the link, but received no response. The only active communication channel with HyperSwap turned out to be invalid. Ultimately, the user speculated that HyperSwap employees might be involved in the theft or deliberately covering it up.

How to Protect Yourself

  • Access exchanges and services only via addresses from official sources, not through links in posts or private messages.
  • Check the account name letter by letter—scammers create duplicates that differ by one or two characters.
  • Do not confirm transactions in your wallet whose purpose is unclear, especially granting permissions to manage tokens.
  • Regularly check and revoke granted permissions through trusted services, entering their address manually.
  • If you suspect theft, revoke all permissions from the compromised wallet as quickly as possible and transfer remaining assets to a new one.

Expert Opinion: This incident is a vivid example that even in decentralized ecosystems with high liquidity, user security remains the weak link. Scammers exploit the human factor, not technical vulnerabilities. Until projects implement mandatory link verification mechanisms and strengthen support, such attacks will continue. Traders should remember: there is no such thing as a free lunch.