The Hyperliquid cryptocurrency ecosystem, rapidly gaining popularity due to its decentralized infrastructure, has faced a serious security incident affecting users of one of its applications — HyperSwap. As a result of a phishing attack conducted through the social network X, attackers stole approximately $12,000 in stablecoins and native tokens.
Anatomy of the Attack: Classic Phishing with an Impersonator
The scheme used by the scammers is not new but remains effective. The victim, who held assets in the HyperSwap liquidity pool, came across a post in what appeared to be the project's official account on X. The post offered a token airdrop, and the link led to a website visually indistinguishable from the real one. A key detail was that the impersonator account differed from the real one by just a couple of characters, and the post itself was published under the official post, creating an illusion of legitimacy.
On the fake website, the victim connected their wallet and, wanting to check their eligibility for free coins, confirmed a transaction. Outwardly, it was no different from standard operations on DeFi platforms. However, in reality, it was granting permission to manage their tokens — the classic mechanism of a "drainer."
Lightning-Fast Theft: Two Minutes to Withdraw Funds
The active phase of the theft took less than two minutes. According to blockchain explorer data, the fraudulent address, labeled as Fake_Phishing3746335, first transferred the NFT representing a share in the liquidity pool to its own wallet. This operation was initiated and paid for by the attacker themselves — the victim was no longer signing anything at that point. This is the danger of drainers: access is obtained in advance, and the withdrawal of funds occurs without the owner's involvement.
Then, all the deposited coins were extracted from the stolen NFT: approximately 3,935 USDC and 116 WHYPE, totaling around $12,100. After that, through the legitimate bridge service LI.FI, all funds were converted into HYPE and sent to the Ethereum network to a one-time "transit" wallet, which was almost immediately emptied.
The Problem with the Project's Response
The reaction of the Hyperliquid and HyperSwap teams deserves special attention. The affected user claims they tried to warn about the scam but faced disregard. According to them, the only active communication channel with HyperSwap (Discord) was non-functional, and attempts to reach the Hyperliquid team through official channels were unsuccessful. This raises serious questions about the ecosystem's readiness for security incidents and its protection of users.
Conclusions and Recommendations
This case is a vivid illustration that even in decentralized and technologically advanced networks, the main vulnerability remains the human factor. Scammers masterfully use social engineering and cloning to bypass even the most reliable smart contracts.
My recommendations:
- Always access dApp websites only through direct links from official sources (documentation, GitHub), not from social media posts.
- Carefully check account names — a difference of one character could cost you all your funds.
- Never sign transactions whose meaning you do not fully understand, especially those granting permission to manage tokens.
- Regularly check and revoke granted permissions through services like Revoke.cash.
Expert opinion: This incident is a wake-up call for the entire Hyperliquid ecosystem. Ignoring security issues and lacking a prompt response to user reports undermines trust in the platform. Until the team establishes a clear process for moderation and threat response, such stories will repeat. Users should be doubly cautious.