A major vulnerability in the Hyperliquid ecosystem has once again drawn attention to user security issues. This time, the victim of a fraudulent scheme was an asset holder on the decentralized exchange HyperSwap, operating on the HyperEVM layer. He lost approximately $12,000 due to the actions of attackers who exploited a fake account on social network X.

According to blockchain explorer data, the incident occurred on June 29, 2026. The user, hoping to receive free tokens (airdrop), clicked on a link from a post that appeared to be from the official HyperSwap account. However, it was actually a carefully crafted fake — the difference in spelling was just a couple of letters, which proved fatal.

Attack Mechanics: From Spoofing to Fund Withdrawal

On the phishing site, the victim connected their wallet and confirmed a transaction, believing they were verifying their eligibility for the airdrop. In reality, this action granted the scammer permission to manage their investment position, structured as an NFT. Externally, such a request is indistinguishable from legitimate transactions on real DeFi services.

The active phase of the theft took place within two minutes (from 20:21 to 20:23 UTC). Using the previously obtained access, the attacker transferred the NFT containing the user's investment to their own wallet. The key point: the owner themselves did not sign anything at that moment — this is precisely the insidiousness of phishing: access is obtained in advance, and the withdrawal of funds occurs later, without the victim's knowledge.

Funds were extracted from the NFT: approximately 3,935 USDC and 116 WHYPE, totaling around $12,100. To cover their tracks, the hacker used the legitimate cross-chain transfer service LI.FI, converting the stolen assets into HYPE and sending about $12,300 from the HyperEVM network to Ethereum. The receiving address on Ethereum was disposable — a typical "transshipment" point that was immediately emptied after the transaction.

Project Response and Systemic Issue

The victim attempted to contact the HyperSwap and Hyperliquid teams via Discord and GitHub to report the dangerous link, which had been active online since June 26. However, according to them, there was no response. The only active communication channel with HyperSwap turned out to be non-functional, and attempts to reach the Hyperliquid ecosystem team also failed. This led the victim to reasonably suspect HyperSwap employees of involvement in the theft, or at least of deliberately concealing the issue.

Expert Commentary: This case is a classic example of how human carelessness and a lack of security measures by projects lead to fund losses. Scammers have perfected the account impersonation scheme to an automatic level, and ecosystems, especially young ones, often ignore signals about vulnerabilities. Users must remember once and for all: clicking links from social media is the primary attack vector. Always verify addresses manually and never blindly sign permissions to manage assets. Projects need to implement automated monitoring systems for phishing clones, otherwise reputational losses will be inevitable.