The rapidly growing Hyperliquid ecosystem has faced a serious security incident. One user lost approximately $12,100 on the decentralized exchange HyperSwap, operating on the HyperEVM layer. The cause is a classic, but no less dangerous, phishing attack originating from a fake link on the social network X (Twitter).
Analysis of blockchain data and materials provided by the victim allows for a full reconstruction of the incident. This is not a protocol hack, but a well-honed social engineering scheme targeting user inattentiveness.
Entry Point: Fake Account and Website Clone
The victim held assets in a liquidity pool on HyperSwap. The right to a share in the pool was confirmed by a unique NFT. It all started when the user saw a post on the official HyperSwap account on X offering a token airdrop. Clicking the link, they landed on a website visually indistinguishable from the real one.
Key point: the post was published not from the exchange's real account, but from an impersonator. The difference in spelling was just a couple of letters, unnoticeable at first glance. The official HyperSwap website leads to one account, while the link to the drainer was placed by a nearly identical clone. The user did not notice the substitution and mistook the fake page for the real one. The attackers' calculation relies precisely on this inattentiveness.
The Theft Mechanism: An Unnoticed Approval
On the fake website, the victim connected their wallet and confirmed a transaction, believing they were simply checking their eligibility for free tokens. In reality, this action granted the scammer permission (approve) to manage their NFT, which confirmed their share in the liquidity pool. Externally, such a confirmation is no different from ordinary operations on legitimate services, so the trick goes unnoticed until the actual withdrawal.
The active phase of the theft took place within two minutes — from 20:21 to 20:23 (UTC) on June 29, 2026. First, the fraudulent address, labeled in the hyperevmscan explorer as Fake_Phishing3746335 (based on a signal from the security service HashDit), used the previously obtained access to transfer the NFT with the user's deposit to its own wallet. Important detail: this operation was initiated and the fee paid by the scammer themselves — the victim did not sign anything at the moment of the theft. This is the essence of the drainer: access is tricked out in advance, and the withdrawal is carried out later, without the owner's involvement.
After this, the attacker withdrew the deposited coins from the NFT: approximately 3935 USDC and 116 WHYPE, totaling around $12,100. Then, through the legitimate bridge and exchange service LI.FI, they converted all the stolen assets into HYPE and sent about $12,300 from the HyperEVM network to the Ethereum network.
Covering Tracks and Project Reaction
In the Ethereum network, the funds arrived at an address created shortly before. It was used only once: received the funds, almost immediately withdrew them in a single operation, and remained practically empty. Such a one-time "transit" wallet is a typical element in the chain of laundering stolen goods.
Upon discovering the loss, the user tried to contact the project team to have the suspicious link removed. However, the link remained in place. According to the victim, the only active communication channel with HyperSwap was Discord, but at the time of the request, it was invalid. The attempt to bring the issue to the attention of the Hyperliquid ecosystem team was also unsuccessful. The victim suggested that HyperSwap employees might be involved in the theft or intentionally covering it up.
How to Protect Yourself from Such Schemes
- Access exchanges and services only via addresses from official sources, not through links in posts or direct messages on social networks.
- Check the account name letter by letter: scammers create platform impersonators differing by one or two letters.
- Do not confirm operations in your wallet whose meaning you do not understand — especially granting permissions to manage tokens and deposits.
- Regularly check and revoke granted permissions through trusted services, typing their address manually.
- If you suspect theft: revoke all permissions from the compromised wallet as quickly as possible and transfer remaining assets to a new one.
Expert Commentary: This case is a vivid illustration that security in DeFi primarily depends on behavioral factors, not just smart contract code. Ecosystems like Hyperliquid, where new, rapidly growing protocols emerge, become ideal targets for phishing attacks. Until project teams establish rapid response to such threats and implement stricter account verification mechanisms, users will have to rely solely on their vigilance. Losing $12,000 is a high price for a lesson that every market participant should learn.