The crypto community is once again facing a serious threat: a user of the decentralized exchange HyperSwap, operating on the Hyperliquid blockchain (HyperEVM layer), lost approximately $12,000 due to a phishing attack. The incident occurred after the victim clicked on a fraudulent link on social media platform X.

My analysis reveals a classic yet no less dangerous scheme: hackers use fake accounts and clone websites to trick users into granting access to their assets. In this case, the attackers created an account nearly indistinguishable from HyperSwap's official profile and posted a promise of a free airdrop.

How the Theft Occurred

The victim held their funds in a HyperSwap liquidity pool, where the share right is confirmed by a unique NFT. Seeing the post from the fake account, the user clicked a link to a fraudulent website, connected their wallet, and confirmed a transaction, thinking they were simply checking eligibility for free tokens. In reality, they granted the scammer permission to manage their investment.

The most critical moment: after gaining access, the hacker did not immediately withdraw the funds. They waited for a convenient time — June 29, 2026, between 20:21 and 20:23 UTC. Within two minutes, the attacker transferred the victim's NFT to their own wallet and then extracted the liquidity: approximately 3,935 USDC and 116 WHYPE, totaling around $12,100.

Covering Tracks

Next, the hacker used the legitimate cross-chain transfer service LI.FI to convert all stolen assets into HYPE and move them to Ethereum. The recipient address was created shortly before the attack and used only once — a typical "transit" wallet that is immediately emptied. This greatly complicates tracking and creates a false impression that the exchange or the swap service itself is to blame.

Notably, the fraudulent address, flagged by the security service HashDit as Fake_Phishing3746335, had been active for about a month and was linked to approximately 25 different wallets. This indicates a well-established, streamlined scheme rather than a random incident.

Project Response

The victim attempted to contact the Hyperliquid and HyperSwap teams to block the malicious link but received no response. The only active communication channel with HyperSwap — Discord — turned out to be non-functional. The user speculated that HyperSwap employees might be involved in the theft or deliberately concealing the issue.

My expert assessment: This case is a serious wake-up call for the Hyperliquid ecosystem. The lack of prompt response to phishing threats and weak user support undermine trust in the platform. I strongly advise investors to access exchanges only through direct links from official sources, check account names letter by letter, and never sign unfamiliar transactions. Security in DeFi begins with your own vigilance.