The Hyperliquid ecosystem has faced a telling security incident that reveals a systemic problem with decentralized platforms. A user fell victim to a phishing attack, losing approximately $12,000 on the decentralized exchange HyperSwap, operating on the HyperEVM network. This is not an isolated case, but part of a well-established scheme targeting inattentive traders.
The events unfolded rapidly. A user, who held assets in the HyperSwap liquidity pool, came across a post on social network X (Twitter). The post was published from a fake account that was visually almost indistinguishable from the official HyperSwap page. The difference was only a couple of characters. By clicking on a link that supposedly led to a site for claiming an airdrop, the user landed on a phishing clone of the resource.
A substitution that went unnoticed
The scammers operated according to a classic, but no less effective, scheme. The fake site was an exact copy of the real one. The user, suspecting nothing, connected their wallet and signed a transaction, thinking they were simply checking their eligibility for free tokens. In reality, they granted the attackers permission to manage their investment, represented as an NFT. This permission outwardly looked no different from standard operations on legitimate services, which allowed the attack to go unnoticed.
Theft in two minutes
The active phase of the theft occurred on June 29, 2026, between 20:21 and 20:23 UTC. First, a spoofed address, flagged by the security service HashDit as Fake_Phishing3746335, used the previously obtained access and transferred the NFT containing the user's investment to its own wallet. Key point: this operation was initiated and paid for by the attacker themselves — the victim did not sign anything at that moment. This is the essence of a drainer: access is tricked out in advance, and the withdrawal of funds happens later, without the owner's involvement.
Then, the scammer extracted the invested funds from the NFT: approximately 3935 USDC and 116 WHYPE, with a total value of around $12,100. Through the legitimate cross-chain transfer service LI.FI, they consolidated all the stolen assets into HYPE and sent approximately $12,300 from the HyperEVM network to the Ethereum network.
How they covered their tracks
On the Ethereum network, the funds arrived at an address created shortly before the theft. It was used only once: it received the funds and almost immediately transferred them further in a single transaction, remaining empty. This "transit" wallet is a typical element in the laundering chain. Using a legitimate service for the cross-network transfer complicates tracking and creates a false impression for the victim that the service or exchange itself is to blame. According to the explorer data, the phishing address was active for about a month and was linked to approximately 25 different wallets, indicating a streamlined operation.
Claims against the project
Upon discovering the loss, the user tried to contact the Hyperliquid project team to have the suspicious link removed, but there was no response. The only active communication channel with HyperSwap was Discord, which was unavailable at the time of writing. The victim speculated that HyperSwap employees might be involved in the theft or deliberately covering it up. The team's disregard for the issue raises serious questions about their responsibility towards users.
Expert opinion: This incident is a stark symptom of a security "blind spot" in DeFi. While project teams focus on smart contract security, they overlook vulnerabilities at the user level, particularly on social media. The lack of an immediate response to phishing attacks is not just negligence, but a direct threat to user capital. Until proactive monitoring systems and rapid response mechanisms for such threats are implemented, such losses will continue to occur.