The Hyperliquid ecosystem, despite its technological appeal, faces serious security challenges. A user contacted me who lost approximately $12,000 on the decentralized exchange HyperSwap, operating on the HyperEVM network. The funds were stolen as a result of a classic phishing attack, organized through a fake link on the social network X.
Anatomy of the Attack: From Spoofing to Theft
The victim held assets in a HyperSwap liquidity pool, where their share was confirmed by a unique NFT. The victim's attention was drawn to a post on what appeared to be the official HyperSwap account, offering an "airdrop." Clicking the link, the user landed on a clone website, visually indistinguishable from the real one. The key detail was the spoofing: the fake account's name differed from the real one by just a couple of characters, and the site was an exact copy.
After connecting their wallet and confirming a transaction, which the victim perceived as verification for receiving free tokens, they effectively granted the scammer permission to manage their NFT investment. This action is the cornerstone of the scheme: the user, unknowingly, signs permission that the attacker later uses.
Technical Implementation and Timeline
The active phase of the theft took less than two minutes, from 20:21 to 20:23 UTC on June 29, 2026. The fraudulent address, flagged by the security service HashDit as Fake_Phishing3746335, used the previously obtained access and transferred the NFT with the victim's investment to its own wallet. The victim themselves did not sign anything at that moment — the transfer fee was paid by the attacker. This is the essence of a "drainer": access is obtained in advance, and the asset withdrawal occurs without the owner's involvement.
Approximately 3935 USDC and 116 WHYPE (totaling ~$12,100) were extracted from the NFT. Then, using the legitimate cross-chain bridge service LI.FI, the scammer converted everything into HYPE and withdrew about $12,300 from the HyperEVM network to Ethereum. It is important to note that a regular, legitimate tool was used to obfuscate the trail, not hacker software. This complicates tracking and creates a false impression that the exchange or service itself is to blame.
Project Response and Systemic Issue
Upon discovering the loss, the victim attempted to contact the HyperSwap and Hyperliquid teams to block the fraudulent link, which had been active since June 26. However, there was no response. The only active communication channel with HyperSwap — Discord — turned out to be non-functional. Attempts to bring the issue to the Hyperliquid team's attention also failed. This raises legitimate questions about the level of user support and the overall security of the ecosystem.
Expert Conclusion
This incident is not an isolated case but a well-established, streamlined scheme. The fraudulent address was active for about a month and is linked to approximately 25 different wallets, indicating a systemic, rather than random, nature of the attacks. The problem here is not a vulnerability in Hyperliquid's or HyperSwap's smart contracts, but the "human factor" and the projects' insufficiently prompt response to threats. Users need to radically reconsider their habits: access exchanges only through direct links from official sources, verify account names letter by letter, and never sign transactions whose purpose is not fully understood. Regular auditing and revocation of granted permissions for asset management should become a mandatory procedure for everyone working with DeFi.