The Hyperliquid ecosystem, despite its innovative nature, is becoming a stage for sophisticated attacks. This time, a user of the decentralized exchange HyperSwap, operating on the HyperEVM layer, fell victim to scammers. Losses amounted to approximately $12,000, and the incident reveals serious gaps in security and project response to threats.
The attack scheme is classic, but no less dangerous for it. It all started when a user saw a post on social network X that appeared to be published by the official HyperSwap account. The post contained a link to a token giveaway — a so-called "airdrop." Clicking the link, the victim landed on a clone site visually indistinguishable from the real one. The only difference was a couple of characters in the URL and the name of the account that published the post.
How the "drainer" works
On the fake site, the user connected their wallet and, thinking they were simply checking eligibility for free coins, signed a transaction. In reality, this action granted the scammer permission to manage their investment in the HyperSwap liquidity pool. The key point: externally, this operation is no different from ordinary confirmations on legitimate services, so the trick goes unnoticed.
The active phase of the theft took less than two minutes. On June 29, 2026, between 20:21 and 20:23 UTC, the fraudulent address (tagged by a security service as Fake_Phishing3746335) used the previously obtained access. It transferred the NFT confirming the user's deposit rights to its own wallet. Most notably: this operation was initiated and paid for by the attacker themselves — the victim did not sign anything at that moment. The funds were then extracted from the NFT: approximately 3,935 USDC and 116 WHYPE, totaling roughly $12,100.
Next, the scammer consolidated all the stolen assets into HYPE via the legitimate cross-chain transfer service LI.FI and withdrew about $12,300 from the HyperEVM network to the Ethereum network, to a disposable "transit" wallet that was immediately emptied. Using a legitimate service for the withdrawal complicates tracking and creates the false impression that the platform itself is to blame for the theft.
Project response and security questions
Upon discovering the loss, the user tried to contact the HyperSwap and Hyperliquid teams to have the fraudulent link, which had been hanging in the comments since June 26, removed. However, according to them, there was no response. The only active communication channel with HyperSwap — Discord — turned out to be non-functional. Attempts to reach the Hyperliquid team through their Discord also failed. The victim even suggested that HyperSwap employees might be involved in the theft or deliberately covering it up.
Explorer data shows that the fraudulent address was active for about a month and is linked to approximately 25 different wallets. This points to a well-established, streamlined scheme, not a random incident.
My comment as an analyst: This case is a stark example of how the rapid development of DeFi infrastructure outpaces security measures. Users must understand: no platform is immune to phishing attacks. The key defense is not technology, but personal vigilance. Always manually check URLs, do not click links from social media posts, and most importantly, never sign transactions whose meaning you do not fully understand. Regularly checking and revoking granted permissions through reliable services is basic hygiene that can save your funds.