The Hyperliquid ecosystem, despite its technological appeal, exhibits alarming security gaps. A user of the decentralized exchange HyperSwap, operating on the HyperEVM layer, lost approximately $12,000. The incident is a classic example of a phishing attack made possible by carelessness and a lack of proper moderation on social media.
How It Happened
The victim held assets in the HyperSwap liquidity pool, where the share right is confirmed by a unique NFT. It all started with a post on social network X (formerly Twitter). The user saw a message, supposedly from the official HyperSwap account, offering a free airdrop. Clicking the link, they landed on a clone site that was visually indistinguishable from the real one.
Key point: the account that published the post was fake. Its name differed from the official one by just a few characters. This type of spoofing is a favorite tactic of scammers, targeting haste or inattention.
The Theft Mechanism: From Permission to Withdrawal
On the fake site, the user connected their wallet and, believing they were checking eligibility for free tokens, signed a transaction. In reality, they granted the scammer permission to manage their NFT, which confirmed their share in the pool. Externally, the transaction was no different from legitimate operations on real services.
The active phase of the theft took less than two minutes — from 20:21 to 20:23 UTC on June 29, 2026. Using the previously obtained access, the attacker simply transferred the victim's NFT to their own wallet. Notably, the transfer transaction itself was initiated and paid for by the hacker — the victim was no longer signing anything at that point. This is the essence of a "drainer": access is tricked out in advance, and the withdrawal of funds occurs later, without the owner's involvement.
Then, the deposited coins were extracted from the stolen NFT: approximately 3,935 USDC and 116 WHYPE (totaling ~$12,100). Through the legitimate cross-chain transfer service LI.FI, the attacker converted everything into HYPE and withdrew about $12,300 from the HyperEVM network to Ethereum.
Project Reaction and Warning Signs
The victim tried to contact the HyperSwap and Hyperliquid teams to point out the fake link, but to no avail. The link to the fraudulent resource had been hanging on social media since June 26. Hyperliquid support on Discord ignored the request, telling the user to deal with HyperSwap on their own.
The only active communication channel with HyperSwap — Discord — was non-functional at the time of writing. This raises serious questions about the teams' responsiveness and their willingness to protect users.
My Conclusions
This case is not an isolated instance of negligence but a systemic security problem within the Hyperliquid ecosystem. While project teams shift responsibility to each other, scammers refine their schemes. Users should learn the main lesson: the only reliable way to access a site is to manually enter the address from official sources, not to click links from posts, even if they look convincing. Regularly checking and revoking granted permissions through verified services is not paranoia but necessary hygiene in the DeFi world.