A major vulnerability in the Hyperliquid ecosystem led to a user of the decentralized exchange HyperSwap losing funds. The victim lost approximately $12,000 in a classic phishing attack, which was made possible due to carelessness and a lack of timely response from the project team.

How the Attack Happened

The affected user held assets in the HyperSwap liquidity pool. The right to a share in the pool was confirmed by a unique NFT. On the official HyperSwap account on social network X, they saw a post offering a free airdrop. By clicking the link, the user landed on a website that visually did not differ from the real one, but was actually a phishing clone.

Key point: The account that published the post was not the official one, but a duplicate whose name differed by just a couple of letters. The victim did not notice the substitution. On the fake website, they connected their wallet and confirmed a transaction, believing they were verifying their eligibility for free tokens. In reality, they granted the scammer permission to manage their investment in the pool.

Timeline of the Theft

The active phase of the incident took less than two minutes — from 20:21 to 20:23 UTC on June 29, 2026. First, the fraudulent address, marked by the security service HashDit as Fake_Phishing3746335, used the previously obtained access and transferred the NFT with the victim's investment to its own wallet. Importantly: this operation was initiated and paid for by the attacker themselves — the victim did not sign anything at that moment. This is the essence of a drainer: access is tricked out in advance, and the withdrawal occurs later, without the owner's involvement.

Then, the scammer extracted approximately 3935 USDC and 116 WHYPE (totaling ~$12,100) from the NFT. Using the legitimate cross-chain transfer service LI.FI, they converted everything into HYPE and moved the funds from the HyperEVM network to the Ethereum network, to a one-time "transit" wallet. This address was created shortly before the transaction, received the funds, and immediately sent them further, remaining practically empty.

Team Response and Risks

Upon discovering the loss, the user tried to contact the HyperSwap team to block the phishing link. However, the link remained active. According to the victim, the only active communication channel with HyperSwap was Discord, which turned out to be invalid at the time of contact. An attempt to report the issue to the Hyperliquid team was also unsuccessful — the user was told to contact HyperSwap themselves.

This case demonstrates a systemic security problem within the ecosystem. The fraudulent address had been active for about a month and was linked to approximately 25 different wallets, indicating a well-established, streamlined scheme rather than an isolated incident.

Precautionary Measures

  • Access exchanges and services only via addresses from official sources, not through links in social media posts.
  • Carefully check the account name: scammers create duplicates that differ by one or two letters.
  • Never confirm operations in your wallet whose meaning you do not understand, especially granting permissions to manage tokens.
  • Regularly check and revoke granted permissions through trusted services.
  • At the slightest suspicion of theft — immediately revoke all permissions from the compromised wallet and transfer remaining assets to a new one.

Expert Opinion: This incident is a stark example of how the lack of prompt support and proactive security from DeFi projects turns the ecosystem into a "blind spot" for users. Hyperliquid and HyperSwap need to fundamentally rethink their threat response procedures, otherwise trust in the platform will be completely undermined.