The Hyperliquid ecosystem, despite its technological appeal, is becoming an increasingly attractive target for malicious actors. This attack targeted a user of the decentralized exchange HyperSwap, operating on HyperEVM, who lost approximately $12,000. This incident is not a protocol hack, but a classic, well-honed phishing scheme that exposes systemic gaps in the security of user interaction with DeFi projects.
The victim, who held assets in the HyperSwap liquidity pool, stumbled upon a fake account on social network X. The counterfeit profile mimicked the official exchange account, differing by just a couple of letters. From this account, a link was posted to a clone website, supposedly offering an airdrop. After clicking the link, the user connected their wallet and confirmed a transaction, believing they were checking their eligibility for free tokens. In reality, they granted the attacker permission to manage their investment — a classic technique using a so-called "drainer."
Key point: the theft itself occurred without the victim's further involvement. First, the scammer gained access to the NFT confirming the pool share, and then, within two minutes (from 20:21 to 20:23 UTC on June 29, 2026), withdrew all funds. The attacker's address, flagged by the security service HashDit as Fake_Phishing3746335, transferred the NFT with the victim's stake to their own wallet, after which they extracted approximately 3935 USDC and 116 WHYPE, converting everything into HYPE via the legitimate service LI.FI and sending it to the Ethereum network.
Blind Spot of Responsibility
The most alarming aspect of this story is the reaction (or rather, the lack thereof) from the HyperSwap and Hyperliquid teams. The victim tried to contact the project through Discord, but the communication channel was inactive. An appeal to Hyperliquid support was also ignored: the user was told to resolve the issue independently with the HyperSwap team. This creates a dangerous precedent where a project providing the infrastructure effectively disclaims responsibility for the security of users operating within its ecosystem.
The link to the fraudulent resource remained active in messages from June 26, indicating either gross negligence by the team or a complete inability to monitor threats. The victim even suggested that HyperSwap employees might be involved in the theft or deliberately covering it up. In any case, this is a serious blow to the reputation of the entire Hyperliquid ecosystem.
How to Protect Yourself: A Lesson for All
This case is not an isolated one. Such schemes are becoming increasingly widespread. I recommend that all DeFi users adhere to several strict rules:
- Never click on links from posts or direct messages. Only access exchanges and services via direct addresses from official sources.
- Check the account name letter by letter. Scammers create duplicates that differ by one or two characters.
- Do not sign transactions whose purpose you do not understand. This is especially true for granting permissions to manage tokens.
- Regularly check and revoke granted permissions through trusted services, entering their address manually.
- At the slightest suspicion of theft, immediately revoke all permissions from the compromised wallet and transfer any remaining assets to a new one.
Expert opinion: Until DeFi projects take responsibility for monitoring phishing threats within their social channels, such incidents will occur with alarming regularity. Users are already paying for this with their carelessness, but the cost of a mistake could become even higher if ecosystems do not start implementing proactive security measures.