Decentralized finance continues to attract not only investors but also malicious actors. A recent incident on the HyperSwap platform, operating on the HyperEVM network, clearly demonstrates how even experienced users can fall victim to well-crafted phishing schemes. The loss of approximately $12,000 due to clicking a fake link is not just an accident but the result of a systemic problem in communication between ecosystem projects.
Classic Impersonation Scheme
The attack began with social engineering. Scammers created a fake account mimicking the official HyperSwap profile on social network X. The difference was minimal — just a couple of characters, unnoticeable at a quick glance. Under the guise of a token airdrop, they posted a link to a phishing site that visually copied the original resource. Trusting the post, the user clicked the link and connected their wallet.
Drain in Two Minutes
The key element of the scheme is the so-called "drainer." The victim, thinking they were confirming eligibility for free coins, actually signed a transaction granting the scammer permission to manage their liquidity in the pool. Externally, this action was indistinguishable from normal operations on legitimate services. Within two minutes, on June 29, 2026, the attacker used the obtained access. They transferred the NFT confirming the pool share to their wallet and then withdrew funds — approximately 3,935 USDC and 116 WHYPE. Notably, the theft itself was initiated and the transaction fee paid by the hacker, without the victim's involvement. This is the essence of a drainer: access is tricked out in advance, and the withdrawal occurs later, automatically.
Covering Tracks and Project Response
The stolen funds were consolidated through the legitimate cross-chain bridge LI.FI and withdrawn to the Ethereum network to a one-time "transit" wallet. The affected user attempted to contact the HyperSwap and Hyperliquid teams to report the vulnerability and block the phishing link, which had been publicly available since June 26. However, according to them, there was no response. The only active communication channel with HyperSwap — Discord — was inaccessible, and a request to the Hyperliquid ecosystem support was ignored. This raises serious questions about the security procedures and incident response within the project.
Analyst Conclusions
This case is not an isolated oversight but a symptom of a security "blind spot" in decentralized ecosystems. Scammers are increasingly exploiting the communication gap between the base protocol (Hyperliquid) and applications built on it (HyperSwap). While teams shift responsibility to each other, users lose funds. The only defense is total paranoia: never click links from social media, manually verify wallet addresses, and regularly revoke suspicious permissions through specialized services. The DeFi market must urgently implement unified threat response standards, or trust in it will be completely undermined.