The rapidly growing Hyperliquid ecosystem has found itself at the center of a high-profile incident involving the theft of funds from a user of the HyperSwap decentralized exchange, which operates on the HyperEVM layer. The victim lost approximately $12,000 due to a sophisticated phishing attack. I have analyzed this case in detail to identify the vulnerabilities being exploited by attackers and to provide recommendations for protection.
Anatomy of the Attack: From a Fake Post to NFT Theft
The scheme is classic, but no less dangerous for it. A user, who held assets in a HyperSwap liquidity pool, came across a post on social network X that looked like an official announcement from the exchange. It offered an airdrop — a free distribution of tokens. By clicking the link, the user landed on a clone website that was visually indistinguishable from the real one.
The key element of the attack was account impersonation. The attackers created a duplicate account on X, whose name differed from the official one by just a couple of characters. The user, not noticing the trick, connected their wallet to the fake site and confirmed a transaction, thinking they were verifying their eligibility for free coins. In reality, they had granted permission (approve) to manage their NFT token, which confirmed their share in the liquidity pool.
The Moment of Theft: Two Minutes and $12,000
Events then unfolded rapidly. The active phase of the theft took place within two minutes — from 20:21 to 20:23 UTC on June 29, 2026. The fraudulent address, flagged by the security service HashDit as Fake_Phishing3746335, using the previously obtained access, transferred the NFT with the victim's stake to its own wallet. Importantly: this operation was initiated and paid for by the scammer themselves — the victim did not sign anything at that moment. This is the essence of a drainer: access is obtained in advance, and the withdrawal of funds occurs later, without the owner's involvement.
From the stolen NFT, the attacker extracted approximately 3,935 USDC and 116 WHYPE (totaling ~$12,100). Then, through the legitimate bridge service LI.FI, they converted everything into HYPE and withdrew about $12,300 from the HyperEVM network to Ethereum. To cover their tracks, a one-time "transit" wallet was used, which was immediately emptied. This is a typical element of the money laundering chain.
Project Response and Security Blind Spot
The most alarming part of this story is the team's reaction. The victim tried to contact the developers of Hyperliquid and HyperSwap via Discord to report the fraudulent link, which had been active on the network for several days. However, according to them, there was no response. The only active communication channel with HyperSwap turned out to be non-functional, and attempts to reach the ecosystem team were also unsuccessful. This raises serious questions about the security culture and level of user support on the platform.
My Analysis and Recommendations
This incident is not a coincidence, but a well-honed scheme. The fraudulent address had been active for about a month and was linked to approximately 25 different wallets. This indicates that we are dealing with a professional group, not a one-off hacker. The security blind spot here is not so much a technical vulnerability, but rather the human factor and insufficient moderation of social networks.
My recommendations are extremely simple, but following them could save your assets:
- Access exchanges and services only via direct links from official sources. Never click on links from social media posts or private messages.
- Check the account name letter by letter. Scammers create duplicates that differ by one or two letters.
- Do not confirm wallet operations whose purpose you do not understand. This is especially true for granting permissions to manage tokens and stakes.
- Regularly check and revoke granted permissions through trusted services, entering their address manually.
- At the slightest suspicion of theft — immediately revoke all permissions from the compromised wallet and transfer remaining assets to a new one.
This case is a harsh reminder that in the world of DeFi, the responsibility for security lies primarily with the user himself. Ignoring basic hygiene rules could cost you all your funds.