The Hyperliquid ecosystem, despite its technological appeal, demonstrates serious security gaps that are actively exploited by attackers. One user lost approximately $12,000 on the decentralized exchange HyperSwap (operating on HyperEVM) as a result of a classic but well-executed phishing attack. I have reconstructed the timeline of this incident in detail to identify systemic vulnerabilities.
How It Happened: From Spoofing to Theft
The victim held liquidity in a HyperSwap pool. The right to a share in the pool is confirmed by an NFT with a unique identifier. It all started on social network X: the user saw a post from an account impersonating the official HyperSwap account, promising an airdrop. By clicking the link, they landed on a clone site that was visually indistinguishable from the real one. However, the link concealed a drainer—a tool for emptying wallets.
It is important to understand that HyperSwap is an independent project built on HyperEVM, and Hyperliquid does not directly manage it, just as Ethereum does not manage Uniswap. This creates a "blind spot" of responsibility.
The spoofing was nearly perfect. The impersonator account differed from the official one by just a couple of characters. The user, not noticing the difference, connected their wallet on the fake site. Externally, the confirmation transaction looked routine—like a standard check for eligibility for free tokens. In reality, they signed permission for the attacker to manage their liquidity token (NFT).
Attack Timeline: 2 Minutes to Steal
The active phase took only two minutes—from 20:21 to 20:23 UTC on June 29, 2026. Using the previously obtained permission, the attacker themselves initiated the transfer of the victim's NFT to their own wallet and even paid the fee. The victim did not sign anything at that moment. This is a key feature of the drainer: access is obtained in advance, and the withdrawal of funds occurs later, without the owner's involvement.
The scammer then withdrew the liquidity from the stolen NFT: approximately 3935 USDC and 116 WHYPE (totaling ~$12,100). After that, they used the legitimate cross-chain bridge LI.FI to convert everything into HYPE and transfer about $12,300 to the Ethereum network to a one-time "transit" wallet. The use of a legitimate service complicates tracking and creates a false impression for the victim that the protocol itself was hacked.
Blockchain analysis shows that the scammer's address had been active for about a month and was linked to approximately 25 different wallets. This indicates a well-established, streamlined scheme rather than an isolated incident.
Project Response: Silence and Ignorance
Upon discovering the loss, the victim attempted to contact the HyperSwap and Hyperliquid teams. The link to the fraudulent post remained active for several days. According to the user, all attempts to warn the Hyperliquid team via Discord and GitHub were ignored. The only active communication channel with HyperSwap (Discord) turned out to be non-functional. This raises serious questions about the ecosystem's security and support processes.
My analysis: This incident is a clear symptom of the "growing pains" of young and rapidly expanding ecosystems. The lack of a single center of responsibility for user security and the poor response to identified threats is a direct path to reputational damage. Users must exercise extreme caution: enter dApp addresses manually rather than clicking links, and regularly check and revoke granted permissions for their wallets. Hyperliquid itself needs to implement stricter mechanisms for monitoring and responding to phishing attacks within its ecosystem; otherwise, trust in the platform will be undermined.