The Hyperliquid ecosystem, despite its technological appeal, is becoming fertile ground for scammers. A user fell victim to this attack, losing approximately $12,000 on the decentralized exchange HyperSwap, which operates on the HyperEVM layer. The incident is a classic example of phishing, where social engineering and carelessness lead to a complete loss of funds.
Attack Scheme: A Substitution That Goes Unnoticed
It all started when the victim, who held liquidity in HyperSwap pools, saw a post on social network X published from an account that was visually indistinguishable from the exchange's official profile. The only difference was a couple of characters in the name. The post contained a link to a supposed token giveaway (airdrop).
After clicking the link, the user landed on a clone site that copied the HyperSwap interface one-to-one. There, they were asked to "verify eligibility for the bonus." This required connecting a wallet and confirming a transaction. Unsuspecting, the victim signed an operation that actually granted the scammer permission to manage their tokens (approve).
Key point: Externally, this request was no different from standard actions on real DeFi services. The user didn't even suspect anything was wrong.
Theft in Two Minutes
The active phase of the theft occurred on June 29, 2026, between 20:21 and 20:23 UTC. The attacker, whose address was flagged by the blockchain explorer hyperevmscan as Fake_Phishing3746335 (a signal from the security service HashDit), used the previously obtained access. They transferred the NFT representing the user's share in the liquidity pool to their own wallet.
It's important to understand: the victim didn't sign anything at that moment. The scammer initiated the transfer themselves and paid the fee. This is the essence of how drainers work — access is tricked out in advance, and the withdrawal of funds occurs later, without the owner's involvement.
From the stolen NFT, the attacker extracted approximately 3935 USDC and 116 WHYPE, totaling roughly $12,100. Then, using the legitimate cross-chain bridge service LI.FI, they consolidated all funds into the HYPE token and moved them out of the HyperEVM network to the Ethereum network, where the trail disappeared on a disposable "transit" wallet.
Project Response: Silence in the Face of Threat
Upon discovering the loss, the victim tried to contact the HyperSwap and Hyperliquid teams. However, according to them, the only active communication channel — Discord — was non-functional, and Hyperliquid's support redirected them back to HyperSwap developers, ignoring the issue itself. The fraudulent link on X remained active for several days despite reports.
This raises serious questions about the ecosystem's security. If the project team doesn't respond to reports of phishing, users are left alone to face the threat.
Expert Opinion
This incident is not a coincidence but a well-established scheme. The fraudulent address had been active for about a month and was linked to 25 different wallets. This points to a serial attacker, not a one-off attack. I strongly recommend users of Hyperliquid and all DeFi platforms: never click on links from social media posts, always manually verify the website URL, and most importantly, carefully read what permissions you are signing in your wallet. If an approve request raises even a shadow of doubt — refuse. Your vigilance is the only reliable defense against drainers.