The Hyperliquid ecosystem, rapidly gaining popularity among DeFi enthusiasts, has faced a serious security incident. One user lost approximately $12,000 on the decentralized exchange HyperSwap, operating on the HyperEVM layer. The attack followed a classic, yet no less dangerous, scheme — via a phishing link on social network X. I analyzed this incident in detail, reconstructing the timeline of events using blockchain explorer data, and concluded that this is not a coincidence, but an element of a well-orchestrated fraudulent campaign.

How It Happened: A Substitution That Went Unnoticed

The victim held assets in a liquidity pool on HyperSwap, with their share of the pool confirmed by a unique NFT. In their X feed, the user came across a post, supposedly from the official HyperSwap account, offering a free airdrop. However, the account was a clone — its name differed from the real one by just a couple of letters. The link in the post led not to the official website, but to a clone that was visually indistinguishable from the original. This is precisely what the attackers rely on: a moment of inattention can cost a person all their funds.

The Theft Mechanism: Less Than Two Minutes

On the fake website, the user connected their wallet and confirmed a transaction, believing they were verifying their eligibility for free tokens. In reality, they granted the scammer permission to manage their investment — a classic technique using a drainer. The active phase of the theft occurred between 20:21 and 20:23 (UTC) on June 29, 2026. First, the fraudulent address, labeled by the hyperevmscan explorer as Fake_Phishing3746335, transferred the NFT containing the victim's investment to its own wallet. Notably, this operation was initiated and paid for by the attacker themselves — the victim did not sign anything at that moment. This is the essence of a drainer: access is obtained in advance, and the withdrawal is carried out later, without the owner's involvement.

Then, the deposited coins were extracted from the NFT: approximately 3935 USDC and 116 WHYPE, totaling around $12,100. Through the legitimate exchange service LI.FI, the scammer converted everything into HYPE and sent approximately $12,300 from the HyperEVM network to the Ethereum network. On Ethereum, the funds arrived at a one-time "transit" wallet, which had been created shortly before and used for only one operation — receiving and immediately withdrawing the funds. The use of a legitimate service for cross-chain transfers complicates tracking and creates a false impression for the victim that the service or exchange itself is to blame.

Project Reaction and Community Complaints

Upon discovering the loss, the user attempted to contact the HyperSwap project team via Discord to block the link, but was unsuccessful. According to them, the only active communication channel was invalid. They also tried to report the issue to the Hyperliquid ecosystem team via GitHub, but received no response. The victim suggested that HyperSwap employees might be involved in the theft or deliberately covering it up. Explorer data shows that the fraudulent address was active for about a month and is linked to approximately 25 different wallets, indicating a systematic scheme rather than an isolated incident.

My Analysis: This case is a stark example of how rapidly growing DeFi ecosystems become targets for organized phishing groups. The lack of an immediate response from the HyperSwap and Hyperliquid teams to reports of fraud is a worrying sign. Users must learn the key lesson: never click on links from social networks, even if they appear official. Always check account addresses letter by letter, do not confirm suspicious transactions, and regularly revoke granted permissions through verified services. The Hyperliquid ecosystem, for its part, urgently needs to implement verification and monitoring mechanisms; otherwise, reputational damage could far outweigh the financial losses.