The Hyperliquid ecosystem continues to attract traders' attention, but with growing popularity come new threats. This time, the target of the attack was a user of the decentralized exchange HyperSwap, operating on the HyperEVM. The losses amounted to approximately $12,000, and this incident is not just a random theft, but a carefully planned phishing attack that reveals systemic vulnerabilities in project communications.

The scheme is classic, but no less dangerous for it. The attackers created a duplicate account of the official HyperSwap profile on social network X. The difference in spelling was minimal — just a couple of characters, unnoticeable at a quick glance. Under the guise of a token distribution (airdrop) announcement, they posted a link to a phishing site that visually completely copied the real HyperSwap resource.

Instant theft through management permission

The victim, not noticing the substitution, clicked the link, connected their wallet, and confirmed the transaction, believing they were simply checking their eligibility for free coins. In reality, it was permission to manage liquidity — the scammers gained full access to the NFT that confirmed the user's share in the HyperSwap liquidity pool.

The active phase of the theft took less than two minutes — from 20:21 to 20:23 UTC on June 29, 2026. Using the previously obtained access, the attacker transferred the NFT to their wallet and then withdrew all funds from it: approximately 3,935 USDC and 116 WHYPE, totaling the equivalent of $12,100. Notably, the fee for this operation was paid by the hacker himself — the victim was no longer signing anything at that point. This is a key feature of a drainer: access is obtained in advance, and the withdrawal occurs later, without the owner's involvement.

The stolen assets were then converted into a single HYPE token through the legitimate LI.FI bridge and sent to the Ethereum network to a one-time "transit" wallet, which was immediately emptied. The use of a legitimate service for cross-chain transfers complicates tracking and creates the false impression that the infrastructure itself is to blame for the theft.

Project response: Ignoring and communication breakdown

The victim tried to contact the HyperSwap and Hyperliquid teams to warn them about the fraudulent link, which had been in messages since June 26. However, according to them, there was no response. The only active communication channel with HyperSwap — Discord — turned out to be invalid. Attempts to bring the problem to the attention of the Hyperliquid ecosystem team were also unsuccessful. This raises serious questions about the level of user support and the security of the environment.

Blockchain analysis shows that the fraudulent address, marked by the security service HashDit as Fake_Phishing3746335, had been active for about a month and was linked to approximately 25 different wallets. This indicates a well-established, streamlined scheme, not an isolated incident.

My expert analysis: This case is a clear example of how a "blind spot" in a project's communication strategy becomes the main attack vector. Users of Hyperliquid and its satellites must understand: decentralization does not mean the absence of responsibility for moderating public channels. As long as project teams ignore phishing accounts on social networks, scammers will continue to reap the rewards. The primary defense is your own vigilance and the habit of checking every address and every permission in your wallet, especially when it comes to access to assets.