The rapidly growing Hyperliquid ecosystem appears to have serious security flaws. During my own investigation, I reconstructed in detail the attack scheme against a user of the HyperSwap decentralized exchange, operating on the HyperEVM layer, which resulted in the theft of approximately $12,000. This incident is not a coincidence, but a well-honed mechanism of social engineering.
How it happened: account and website spoofing
The victim, who held assets in the HyperSwap liquidity pool (confirmed by a unique NFT), came across a post on social network X that looked like an official announcement from the exchange. It offered an airdrop. By clicking the link, the user landed on a clone website, visually indistinguishable from the real one. The key element of the deception was a duplicate account, whose name differed from the official one by just a couple of characters. The scammers exploited the victim's inattention, which is their main weapon.
The theft mechanism: a "drainer" in action
On the fake website, the user connected their wallet and signed a transaction. Outwardly, it looked like a standard check for eligibility to receive free tokens. In reality, the victim granted the attacker approval (approve) to manage their NFT, which confirmed their share in the liquidity pool. The entire active phase of the theft took less than two minutes — from 20:21 to 20:23 UTC on June 29, 2026.
The attacker, using the previously obtained access, independently (and paying the fee at their own expense) transferred the victim's NFT to their wallet. They then withdrew funds from it: approximately 3,935 USDC and 116 WHYPE, totaling about $12,100. Afterwards, via the legitimate cross-chain bridge LI.FI, all funds were converted to HYPE and withdrawn to the Ethereum network to a one-time "transit" address.
Project reaction: ignoring the problem
Upon discovering the loss, the victim attempted to contact the Hyperliquid and HyperSwap teams to report the fake link, which had been active since June 26. However, their appeals in the official Hyperliquid Discord were ignored. The Hyperliquid team redirected them to HyperSwap, whose communication channel was non-functional at the time. Such passivity raises serious questions about the level of user support and ecosystem security.
Analyst conclusions
This case is not an isolated one. The scammer's address was active for about a month and is linked to approximately 25 wallets, indicating a serial nature of the attacks. Such incidents represent a security "blind spot," where responsibility lies entirely with the user. Until major projects implement mandatory link verification and active monitoring of phishing clones, we will see more and more such thefts. My advice: always manually check the website URL, never sign unclear transactions, and regularly revoke outdated approvals through specialized services.