A user of the decentralized exchange HyperSwap, operating on the HyperEVM blockchain, recently contacted me. He reported losing approximately $12,000 due to a scam initiated through a fake link on social network X. This is a classic, but no less dangerous, phishing attack that reveals serious security issues within the ecosystem.

I reconstructed the timeline of events in detail using the provided screenshots and blockchain explorer data. The story turned out to be instructive, demonstrating how even experienced users can fall victim to well-crafted schemes.

How It Happened: The Unnoticed Impersonation

The victim held their assets in a shared liquidity pool on HyperSwap. The right to a share in the pool was confirmed by a unique NFT. In the official HyperSwap account on X, they saw a post with a link to a "free airdrop" and, without suspecting anything, clicked on it.

In reality, the post was not published from the exchange's official account, but from a clone impersonator. The account name differed by just a couple of characters, making it nearly imperceptible. The website the link led to was also an exact copy of the original. This is precisely the trick scammers rely on: a moment's inattention can cost all your funds.

On the fake website, the user connected their wallet and confirmed a transaction, believing they were simply verifying their eligibility for free tokens. In reality, they granted the scammer permission to manage their investment. Externally, such a permission request is indistinguishable from normal operations on legitimate services, so the trick goes unnoticed until the actual withdrawal.

The Theft in Two Minutes: Technical Details

The active phase of the theft occurred between 20:21 and 20:23 (UTC) on June 29, 2026. The scammer's address, labeled by the hyperevmscan explorer as Fake_Phishing3746335 (a security alert from HashDit), used the previously obtained access to transfer the NFT containing the user's investment to their own wallet.

Key detail: this operation was initiated by the scammer themselves, who also paid the fee — at the moment of the theft, the victim did not sign anything. This is the essence of a drainer: access is obtained in advance, and the withdrawal is carried out later, without the owner's involvement.

The attacker then extracted the deposited coins from the NFT: approximately 3,935 USDC and 116 WHYPE, totaling around $12,100. Through the legitimate exchange and transfer service LI.FI, they converted all the stolen assets into HYPE and sent approximately $12,300 from the HyperEVM network to the Ethereum network.

Covering Tracks and Project Response

On the Ethereum network, the funds arrived at a disposable "intermediary" wallet, which had been created shortly before and was immediately emptied. This is a standard element in the money laundering chain.

Notably, the scammer used not some "hacker" tool for the withdrawal, but a regular, legitimate cross-chain transfer service. This complicates tracking and creates a false impression for the victim that the service or exchange itself is to blame.

When the user discovered the loss, they tried to contact the HyperSwap team to block the phishing resource. However, according to them, the only active communication channel was Discord, which turned out to be non-functional at the time. They also attempted to bring the issue to the attention of the Hyperliquid ecosystem team, but that attempt also failed. The link to the fraudulent resource remained online for several days.

The victim suggested that HyperSwap employees might be involved in the theft or deliberately covering it up. This is, of course, a serious accusation, but it highlights the extreme frustration and distrust caused by the project's inaction.

How to Protect Yourself from Phishing

  • Access exchanges and services only through addresses from official sources, not via links in posts or private messages.
  • Check the account name on X character by character: scammers create impersonators that differ by one or two letters.
  • Never confirm operations in your wallet whose purpose you do not understand, especially granting permissions to manage tokens and investments.
  • Regularly check and revoke issued permissions through verified services, typing their address manually.
  • If you suspect a theft, revoke all permissions from the compromised wallet as quickly as possible and transfer remaining assets to a new one.

Analyst's Opinion. This incident is a clear example that security in DeFi is not just about smart contract code, but also about the operational security of the projects themselves. Ignoring phishing threats and the lack of prompt response to user requests from the HyperSwap and Hyperliquid teams undermines trust in the entire ecosystem. Users should be extremely vigilant and remember: there's no such thing as a free lunch, especially in the world of cryptocurrencies.