The Hyperliquid ecosystem, despite its technological appeal, demonstrates a troubling vulnerability in user security. Recently, I documented an incident where a victim lost approximately $12,000 on the decentralized exchange HyperSwap, operating on the HyperEVM network. The funds were stolen due to clicking a fraudulent link on social network X.

By reconstructing the timeline of events using blockchain explorer data, I identified a classic phishing scheme that, unfortunately, remains one of the most effective in the cryptocurrency space.

How It Happened: From Bait to Theft

The affected user held assets in a HyperSwap liquidity pool. The right to a share in the pool was confirmed by an NFT with a unique number. In the feed of an account that visually was almost indistinguishable from the official HyperSwap profile, they saw a post promising a free airdrop. Hidden behind the link was a drainer—a malicious tool for automatically withdrawing funds.

The scammers created a duplicate account, differing from the real one by just a couple of characters. The user did not notice the substitution and went to a clone site that looked absolutely convincing. There, they connected their wallet and confirmed a transaction, thinking they were verifying their eligibility for free tokens. In reality, they granted the attacker permission to manage their investment.

The Theft Timeline: Less Than Two Minutes

The active phase of the attack occurred between 20:21 and 20:23 UTC on June 29, 2026. First, the fraudulent address, flagged by the security service HashDit as Fake_Phishing3746335, used the previously obtained access and transferred the victim's NFT with their investment to its own wallet. Key point: the transfer operation itself was initiated and paid for by the hacker; the victim did not sign anything at that moment. This is the essence of a drainer—access is tricked out in advance, and the withdrawal is carried out later, without the owner's involvement.

The attacker then extracted the invested coins from the NFT: approximately 3,935 USDC and 116 WHYPE, totaling roughly $12,100. Through the legitimate exchange service LI.FI, they consolidated all the stolen assets into HYPE and sent about $12,300 from the HyperEVM network to the Ethereum network to a disposable "transit" wallet.

Project Response: Deafness and Inaction

Upon discovering the loss, the user tried to contact the project team to block the link. However, they faced complete disregard. The only active communication channel with HyperSwap was Discord, but at the time of the incident, it turned out to be invalid. Attempts to report the issue to the Hyperliquid team through their support also failed. The link to the fraudulent resource remained active from June 26.

My analysis: This case is not an isolated mistake but a systemic failure in the ecosystem's communication and security. Hyperliquid, as the base layer, should be responsible for monitoring and blocking obvious phishing schemes within its network. Ignoring such incidents undermines trust in the entire project. Users should double-check every link, especially on social media, and never sign unclear transactions—the cost of a mistake can be too high.