Another alarming signal has emerged in the DeFi world, one that should compel every user to reconsider their security habits. This time, the Hyperliquid ecosystem, specifically its decentralized exchange HyperSwap, has come under attack. A victim who held assets in a liquidity pool lost approximately $12,000 due to a classic, yet no less dangerous, phishing attack.

The Deception Scheme: Account and Website Spoofing

It all began when a user saw a post on social network X (formerly Twitter) that appeared to be an official message from HyperSwap. It offered an airdrop — a free distribution of tokens. Clicking the link, the victim landed on a website visually indistinguishable from the real one. However, behind this facade lurked a drainer — a malicious tool designed to steal funds from a crypto wallet.

The key element of the attack was a clone account. The fake profile's name differed from the official one by just a couple of letters, making it nearly imperceptible at a glance. The scammers created a convincing copy of both the social media page and the HyperSwap website itself. The user, not noticing the substitution, connected their wallet to the fraudulent resource.

The Moment of Theft: Less Than Two Minutes

On the fake website, the victim confirmed an operation, believing they were verifying their eligibility for free coins. In reality, they granted the scammer permission to manage their investment, which was secured by a unique NFT. This action outwardly appeared no different from standard transactions on legitimate services.

The active phase of the theft occurred between 20:21 and 20:23 UTC on June 29, 2026. The fraudulent address, flagged by the security service HashDit as Fake_Phishing3746335, used the obtained access and transferred the NFT with the investment to its own wallet. It is important to note: the operation was initiated by the attacker themselves, who also paid the fee. The victim did not sign anything at that moment — this is the essence of a drainer: access is tricked out in advance, and the withdrawal of funds happens later, without the owner's involvement.

From the stolen NFT, the attacker extracted approximately 3935 USDC and 116 WHYPE, totaling around $12,100. Then, using the legitimate cross-chain transfer service LI.FI, they converted everything into HYPE and withdrew about $12,300 from the HyperEVM network to the Ethereum network.

Project Response: Deafening Silence

Upon discovering the loss, the victim tried to contact the HyperSwap and Hyperliquid teams to report the fraudulent link that was still active on social media. However, their efforts were unsuccessful. The only active communication channel with HyperSwap — Discord — was non-functional at the time of the request. Attempts to bring the issue to the attention of the Hyperliquid ecosystem team were also ignored.

The victim reasonably suspected that HyperSwap employees might be involved in the theft or, at the very least, deliberately concealing it. This incident exposes a serious problem: decentralized projects often do not take responsibility for user security, shifting it onto the participants themselves. While scammers are becoming increasingly sophisticated, the response from platforms remains frustratingly slow.

How to Protect Yourself: Practical Tips

  • Access exchanges and services only via addresses from official sources, not through links in posts or direct messages.
  • Check account names letter by letter: scammers often create clones differing by one or two characters.
  • Never confirm operations in your wallet whose purpose you do not understand, especially granting permissions to manage tokens.
  • Regularly check and revoke granted permissions through verified services, manually entering their addresses.
  • If you suspect theft, immediately revoke all permissions from the compromised wallet and transfer remaining assets to a new one.

Expert Comment: This case is a stark example of how human error and insufficient vigilance become the main vulnerability in DeFi. Until project teams actively moderate their communities and respond promptly to threats, such attacks will continue. Users should remember: there is no such thing as a free lunch, and in cryptocurrencies, it often comes with a drainer.