A user of the decentralized exchange HyperSwap, operating on the Hyperliquid blockchain (HyperEVM layer), contacted me. He reported losing approximately $12,000. The funds were stolen in a classic phishing attack initiated through a fake link on social network X.
Analysis of the provided data and blockchain explorer records allowed me to fully reconstruct the timeline of the incident. This involves a well-established scheme, not a random error.
How It Happened
The victim held assets in a HyperSwap liquidity pool. The right to a share in the pool was confirmed by a unique NFT. On his X feed, he came across a post from an account that was visually indistinguishable from the official HyperSwap profile. The post offered an "airdrop" — a free token distribution. Clicking the link, the user landed on a clone website, where he was prompted to "verify eligibility for the bonus."
On this fake website, he connected his wallet and confirmed a transaction. Externally, it was no different from standard operations on legitimate DeFi services. In reality, he granted the scammer permission (approve) to manage his liquidity NFT.
The Moment of Theft
The active phase of the attack took place within two minutes — from 20:21 to 20:23 UTC on June 29, 2026. Using the previously obtained permission, the scammer himself initiated the transfer of the NFT from the victim's wallet to his own address. Key point: the theft itself was carried out by the attacker, who paid the gas fee for the transaction. The victim did not sign anything at that moment. This is the essence of a "drainer": access is tricked out in advance, and the withdrawal of funds occurs later, without the owner's knowledge.
After obtaining the NFT, the scammer withdrew its liquidity: approximately 3935 USDC and 116 WHYPE, totaling roughly $12,100. Then, using the legitimate cross-chain bridge LI.FI, he converted everything into HYPE and transferred about $12,300 to the Ethereum network.
Traces and Response
On the Ethereum network, the funds arrived at a disposable "transit" wallet, which was created shortly before and immediately emptied. This is standard practice for covering tracks. It is important to emphasize: a regular, legitimate service was used for the withdrawal, which complicates tracking and may create a false impression that the exchange or bridge was involved in the theft.
The scammer's address, flagged by the security service HashDit as Fake_Phishing3746335, was active for about a month and linked to approximately 25 different wallets. This indicates a serial, industrialized scheme.
The victim tried to contact the Hyperliquid and HyperSwap teams to block the phishing link but received no response. The link remained active. The only communication channel with HyperSwap (Discord) was invalid at the time.
How to Protect Yourself
- Always access exchange and service websites only through direct links from official sources (e.g., CoinMarketCap), not from social media posts.
- Carefully check the account name on X. Scammers use impersonators that differ by one or two letters.
- Never sign transactions whose meaning you do not fully understand. This is especially true for granting permissions (approve) to manage tokens and NFTs.
- Regularly check and revoke granted permissions through verified services, entering their address manually.
- At the slightest suspicion of theft — immediately revoke all permissions from the compromised wallet and transfer remaining assets to a new one.
Expert Opinion: This case is a stark illustration of a "blind spot" in security within the Hyperliquid ecosystem. Primary responsibility lies with the HyperSwap team, which failed to ensure the security of its communication channel and moderate it in a timely manner. However, users must also learn a harsh lesson: trusting links from social networks, even if they look official, is a direct path to losing funds. The era of blindly clicking on "airdrops" is over.