The Hyperliquid ecosystem, at first glance, appears to be a model of decentralization and security. However, a recent incident on the decentralized exchange HyperSwap, operating on the HyperEVM network, has exposed a critical "blind spot" in user protection. A victim lost approximately $12,000, and this is far from an isolated case.

My analysis of the chain of events, reconstructed from blockchain explorer data, reveals a classic yet no less dangerous phishing scheme that calls into question the level of responsibility of both the dApps themselves and the parent platform.

Perfect Impersonation: From Fake Account to Theft

It all started when a user, who held liquidity in the HyperSwap pool, saw a post on social network X from an account visually indistinguishable from the exchange's official profile. The difference was just a couple of characters. The post promised an "airdrop" and led to a clone site that replicated HyperSwap's design one-to-one.

Key point: The victim, not noticing the impersonation, connected their wallet to the phishing site and, thinking they were simply checking eligibility for free tokens, signed a transaction. In reality, it was a "drainer" — a malicious smart contract that requested permission to manage the user's assets. The approval transaction itself looked no different from standard operations on legitimate services, which misled the victim.

Attack Timeline: Less Than Two Minutes

The active phase of the theft occurred on June 29, 2026, between 20:21 and 20:23 UTC. First, the fraudulent address (tagged by security service HashDit as Fake_Phishing3746335) used the previously obtained access to transfer the NFT, confirming the share in the liquidity pool, to its own wallet.

Important: This transaction was initiated and paid for by the scammer themselves. The victim did not sign anything at this moment. This is the essence of a drainer — access is obtained in advance, and the asset withdrawal occurs later, without the owner's knowledge.

After that, the attacker withdrew the locked funds from the NFT: approximately 3935 USDC and 116 WHYPE, totaling roughly $12,100. To cover their tracks, they used the legitimate cross-chain bridge LI.FI, converting all stolen assets into HYPE and sending about $12,300 from the HyperEVM network to the Ethereum network.

The Problem of Responsibility: Who Is to Blame?

The most alarming aspect of this story is the reaction (or rather, the lack thereof) from the Hyperliquid team. The affected user repeatedly tried to warn the project about the existence of a phishing link that had been lingering in the comments of official posts since June 26. They contacted support via Discord but received a standard response: "contact the HyperSwap team directly."

This creates a dangerous precedent. HyperSwap is an independent application on HyperEVM, and logically, Hyperliquid is not responsible for it. However, when scammers actively use the ecosystem's official communication channels (X, Discord), and the parent project's team ignores threat signals, this is a direct disregard for basic security principles.

My analysis shows that the fraudulent address was active for about a month and is linked to approximately 25 different wallets. This indicates not a random attack, but a well-oiled, streamlined scheme.

How to Protect Yourself: Basic but Critically Important Rules

  • Access websites only through direct links from official sources (e.g., CoinGecko, DeFi Llama), not from social media posts.
  • Check the account name letter by letter. Scammers create lookalikes differing by 1-2 characters.
  • Never sign transactions whose purpose you do not understand. This is especially true for granting permissions (approve) to manage tokens.
  • Regularly check and revoke granted permissions through trusted services (e.g., revoke.cash), entering their address manually.
  • At the slightest suspicion of theft, immediately revoke all permissions from the compromised wallet and transfer remaining assets to a new one.

My expert opinion: The HyperSwap incident is a wake-up call for the entire industry. As long as L1/L2 platform teams distance themselves from the security issues of applications built on their infrastructure, phishing will remain a "trump card" for hackers. Users must realize: in the world of DeFi, your security is 99% your personal responsibility, and "decentralization" does not equal "absence of scammers." The lack of a swift response and a clear reporting system from Hyperliquid is a systemic vulnerability that will cost users millions more dollars until it is fixed.