The Hyperliquid ecosystem, despite its rapid growth and popularity, continues to exhibit serious security gaps that are actively exploited by malicious actors. Another incident occurred on the decentralized exchange HyperSwap, operating on the HyperEVM layer. A victim holding assets in a liquidity pool lost approximately $12,000 due to a classic, yet no less dangerous, phishing scheme.

The Impersonator That Went Unnoticed

The attack scheme is painfully familiar but continues to work. A post appeared on social network X (formerly Twitter) from an account that was visually almost indistinguishable from the official HyperSwap profile. The difference was just a couple of characters. The post contained a link to a clone website, supposedly offering a free token airdrop.

The user, failing to notice the substitution, clicked the link and connected their wallet to the fraudulent resource. Externally, the interface of the imitation site completely copied the legitimate platform. Believing they were simply checking their eligibility for free tokens, the victim confirmed a transaction that actually granted the attacker permission to manage their stake (an NFT confirming their share in the liquidity pool).

Theft in Two Minutes

The active phase of the attack took less than two minutes. According to blockchain explorer data, on June 29, 2026, at 20:21 UTC, the fraudulent address, flagged by the HashDit security system as Fake_Phishing3746335, used the previously obtained access to transfer the victim's staked NFT to its own wallet. It is important to note that the transfer transaction itself was initiated and paid for by the attacker — the victim did not sign anything at that moment. This is the insidious nature of the drainer: access is tricked out in advance, and the withdrawal occurs later, without the owner's involvement.

Afterwards, the hacker withdrew funds from the stolen NFT: approximately 3935 USDC and 116 WHYPE, totaling about $12,100. Then, using the legitimate cross-chain bridge service LI.FI, they converted everything into HYPE and sent about $12,300 from the HyperEVM network to the Ethereum network, where the funds were lost to tracking through a one-time "transit" wallet.

Project Response and Conclusions

The affected user attempted to contact the Hyperliquid team to report the fraudulent link, which had been active since June 26, but according to them, did not receive an adequate response. Ultimately, the link remained active in the community, posing a threat to other participants. The very fact of using a legitimate service to withdraw funds complicates tracking and creates the false impression that the platform or the bridge itself is to blame for the theft.

Expert Opinion: This incident is not an isolated case but a well-established scheme that will be repeated over and over. Responsibility for the security of one's assets in DeFi lies primarily with the user. It is necessary to develop an ironclad habit: never click on links from social networks, always verify the wallet address and website URL character by character, and regularly review and revoke granted permissions through specialized services. Ignoring these simple rules could cost you all your funds.