The Hyperliquid ecosystem, despite its technological appeal, continues to be a stage for sophisticated attacks. This time, a user of the decentralized exchange HyperSwap, operating on the HyperEVM layer, became the target. As a result of a phishing attack, they lost approximately $12,000. Let's break down the details of this incident, which reveals a critical "blind spot" in user security.

Anatomy of the Attack: From Post to Theft

The scheme the victim encountered is painfully familiar, but no less dangerous for it. It all started when, on social network X (formerly Twitter), they came across a post supposedly published by the official HyperSwap account. The post offered an airdrop — a free token distribution. Clicking the link, the user landed on a site visually indistinguishable from the real one.

The key element of the attack was account impersonation. The scammers created a duplicate of the official HyperSwap page, changing just a couple of letters in the name. Without noticing the trick, the user connected their wallet to the phishing site and confirmed a transaction, thinking they were checking their eligibility for free coins. In reality, they granted the attackers permission to manage their investment in a liquidity pool, which was confirmed by a unique NFT.

Two Minutes That Decided Everything

The active phase of the theft took less than two minutes — from 20:21 to 20:23 UTC on June 29, 2026. Using the previously obtained access, the scammer simply transferred the NFT with the victim's investment to their own wallet. Notably, the victim did not sign anything at that moment — this is the essence of a "drainer": access is tricked out in advance, and the withdrawal happens later, without the owner's involvement.

After this, the attacker extracted the funds from the NFT — approximately 3935 USDC and 116 WHYPE, totaling about $12,100. Then, using the legitimate bridge service LI.FI, they converted everything into HYPE and withdrew about $12,300 from the HyperEVM network to the Ethereum network, where the trail quickly disappeared on a one-time "transit" wallet.

The Problem of Communication and Responsibility

The most alarming part of this story is the reaction (or rather, the lack thereof) from the project. The victim tried to contact the Hyperliquid and HyperSwap teams to warn them about the fraudulent link, which had been active in messages since June 26. However, their appeals via Discord and other channels were ignored. The link remained active, and the only communication channel with HyperSwap turned out to be non-functional.

The user even suggested that HyperSwap employees might be involved in the theft or deliberately covering it up. Although this is just a theory, the fact that the team ignored the problem raises serious questions about their attitude towards user security.

Conclusions and Recommendations

This incident is a classic example of phishing, which, unfortunately, remains one of the most effective tools in the arsenal of attackers. Scammers exploit trust, inattention, and the desire for freebies.

How to protect yourself:

  • Always access exchanges and services only through addresses from official sources, not through links in posts.
  • Carefully check account names — scammers often create duplicates with minor differences.
  • Never confirm transactions whose meaning you do not understand, especially those granting permissions to manage tokens.
  • Regularly check and revoke issued permissions through trusted services.
  • At the slightest suspicion of theft — immediately revoke all permissions from the compromised wallet and transfer remaining assets to a new one.

My comment as an analyst: The HyperSwap story is not an isolated incident but a systemic problem across the entire DeFi ecosystem. Projects, especially in early stages, often neglect basic security measures, shifting all responsibility onto users. Until teams start actively monitoring phishing resources and responding promptly to threats, such incidents will continue. User vigilance is good, but proactive security from the platform is a necessity.