The Hyperliquid ecosystem, despite its technological progress, continues to demonstrate vulnerabilities that attackers successfully exploit. This time, the target of the attack was a user of the decentralized exchange HyperSwap, operating on the HyperEVM base. As a result of a phishing scheme, he lost approximately $12,000.
An analysis of the incident, conducted based on data from a blockchain explorer, revealed a classic, but no less dangerous, scheme — phishing through fake links on social networks.
How It Happened: A Step-by-Step Breakdown of the Attack
The victim, who held liquidity in HyperSwap pools, came across a post on X (formerly Twitter) from an account that was visually indistinguishable from the exchange's official profile. The difference was only in a couple of characters. The post contained a link supposedly leading to a website for claiming an airdrop. After clicking on it, the user landed on a phishing site, an exact copy of the real one.
On the fake resource, he connected his wallet and, believing he was checking his eligibility for free tokens, signed a transaction. Outwardly, it was no different from regular operations on legitimate services. However, in reality, this action granted the scammer permission to manage his investment in the liquidity pool, which was confirmed in the form of an NFT.
The active phase of the theft took less than two minutes — from 20:21 to 20:23 UTC on June 29, 2026. The attacker, using the previously obtained access, transferred the NFT with the investment to his wallet. It is important to note: the transfer transaction itself was initiated and paid for by the scammer. The victim did not sign anything at that moment. This is the essence of how a "drainer" works — access is tricked out in advance, and the withdrawal of assets occurs later, without the owner's involvement.
After that, the scammer withdrew the invested funds from the NFT — approximately 3,935 USDC and 116 WHYPE (totaling around $12,100). Then, through the legitimate bridge service LI.FI, he converted everything into HYPE and sent about $12,300 from the HyperEVM network to the Ethereum network, to a freshly created "transit" wallet, which remained empty after this operation.
Project Response and Security Concerns
Upon discovering the loss, the user tried to contact the HyperSwap and Hyperliquid teams to report the fraudulent link. However, according to him, the response was zero. The only active communication channel with HyperSwap — Discord — turned out to be non-functional. Attempts to bring the issue to the attention of the ecosystem team were also unsuccessful.
The victim suggested that HyperSwap employees might be involved in the theft or deliberately covering it up. The scammer's address, flagged by the security service HashDit as Fake_Phishing3746335, had been active for about a month and was linked to approximately 25 different wallets. This indicates a well-established, streamlined scheme, rather than a random incident.
My comment: This incident is a clear example that in the DeFi world, the main vulnerability lies not in smart contract code, but in the human factor. Users must be extremely vigilant and always check wallet addresses and account names. Projects, for their part, are obligated to respond promptly to reports of phishing resources; otherwise, they risk not only their reputation but also the trust of the entire community.