The Hyperliquid ecosystem, despite its popularity, demonstrates alarming security gaps that are actively exploited by scammers. A user contacted our editorial team who lost approximately $12,000 on the decentralized exchange HyperSwap, operating on the HyperEVM network. The funds were stolen as a result of a classic phishing attack via a fake link on social network X.

A detailed analysis of the incident, conducted based on the provided data and blockchain explorer records, revealed a well-established scheme that calls into question the project team's response.

How it happened: a substitution that went unnoticed

The victim held their assets in a HyperSwap liquidity pool, confirming their share entitlement through a unique NFT. In an official thread of the HyperSwap account on X, they saw a post promising a free airdrop and clicked the link. However, behind it was not the official website, but a drainer—a tool for stealing cryptocurrency.

The key moment of the attack was account spoofing. The scammers created a duplicate of the official HyperSwap page, changing just a couple of letters in the name. The user, not noticing the trick, mistook the fake for the real one. On the clone site, they connected their wallet and confirmed a transaction, believing they were simply verifying their eligibility for free tokens. In reality, they granted the attacker permission to manage their investment.

Timeline of the theft: less than two minutes

The active phase of the theft occurred between 20:21 and 20:23 UTC on June 29, 2026. First, the fraudulent address, tagged by the security service HashDit as Fake_Phishing3746335, used previously obtained access and transferred the victim's NFT with their investment to its own wallet. Importantly, this operation was initiated and paid for by the attacker himself—the victim did not sign anything at that moment. This is the essence of how a drainer works: access is obtained in advance, and the withdrawal is carried out later, without the owner's involvement.

Then, the scammer withdrew the invested coins from the NFT—approximately 3,935 USDC and 116 WHYPE, totaling around $12,100. After that, using the legitimate exchange service LI.FI, they converted all the stolen assets into HYPE and withdrew about $12,300 from the HyperEVM network to Ethereum.

Project response: silence and disregard

Upon discovering the loss, the user attempted to contact the HyperSwap and Hyperliquid teams to report the dangerous link, which had been active since June 26. Their attempts to warn about the scam via Discord and GitHub received no response. The Hyperliquid team redirected them back to HyperSwap, whose only communication channel (Discord) was invalid at the time. The victim reasonably suspected that HyperSwap employees might be involved in the theft or deliberately concealing it.

How to protect yourself

  • Access exchanges only via addresses from official sources, not through links from posts or private messages.
  • Check the account name letter by letter: scammers create duplicates that differ by one or two letters.
  • Do not confirm wallet operations whose purpose is unclear, especially granting permissions to manage tokens.
  • Regularly check and revoke granted permissions through trusted services.
  • If you suspect theft—revoke all permissions from the compromised wallet as quickly as possible and transfer remaining assets to a new one.

Expert opinion from Cryptalist: This incident is a clear example of how decentralization shifts all responsibility for security onto the user, yet the ecosystem does not provide them with adequate protection tools. The Hyperliquid team's disregard for reports of fraud within its sidechain is not just negligence, but a direct threat to all network participants. Until such "blind spots" are eliminated, trust in HyperEVM will continue to be undermined by similar incidents.