The Hyperliquid ecosystem, despite its technological sophistication, is becoming an increasingly attractive target for malicious actors. A user of the HyperSwap decentralized exchange, operating on the HyperEVM layer, fell victim to such an attack, losing approximately $12,000. The incident is a classic example of phishing, based on inattention and trust in seemingly official sources.
How it happened
The victim was a liquidity provider on HyperSwap, confirming their right to a share in the pool through a unique NFT. In the project's official account on social network X (formerly Twitter), they saw a post promising a free airdrop. Clicking the link, the user landed on a website visually indistinguishable from the real one, where to "verify eligibility for tokens," they were required to connect their wallet and confirm a transaction. In reality, the link concealed a drainer — a tool for stealing funds from crypto wallets.
The key element of the scheme was account spoofing. The attacker created a duplicate of the official HyperSwap page, changing just a couple of characters in the name. The user did not notice the substitution and took the fake at face value. By confirming what seemed like a harmless operation, they effectively granted the scammer permission to manage their investment, recorded in the NFT.
Timeline of the theft
The active phase of the attack took less than two minutes. On June 29, 2026, between 20:21 and 20:23 UTC, the fraudulent address, labeled by the hyperevmscan explorer as Fake_Phishing3746335, used the previously obtained access. It transferred the NFT with the victim's investment to its own wallet, paying the transaction fee itself. The victim did not sign anything at that moment — this is the essence of the drainer: access is obtained in advance, and the withdrawal of funds occurs later, without the owner's involvement.
After this, the attacker extracted the locked assets from the NFT: approximately 3,935 USDC and 116 WHYPE (totaling around $12,100). Then, using the legitimate cross-chain transfer service LI.FI, they consolidated everything into HYPE and moved the funds from the HyperEVM network to Ethereum.
Project response and systemic issue
Upon discovering the loss, the user tried to contact the Hyperliquid team via Discord to report the malicious link, which was still hanging in the comment thread. According to them, the response was zero — support redirected them back to the HyperSwap team. Meanwhile, the only active communication channel with HyperSwap itself was non-functional, worsening the situation. The victim reasonably suspected that HyperSwap employees might either be involved in the theft or deliberately covering it up.
The fraudulent address was active for about a month and was linked to approximately 25 different wallets. This indicates a well-established, streamlined scheme rather than a random incident. A regular, legitimate service was used to withdraw the funds, making tracking difficult and creating the false impression that the exchange or bridge itself was at fault.
Analyst's opinion: This case is a vivid illustration that security in DeFi is, first and foremost, the user's personal responsibility. No technology will protect against phishing if basic rules are not followed: checking URLs and account names letter by letter, never clicking links from social media posts, and regularly reviewing and revoking granted permissions. Until projects implement stricter verification and moderation mechanisms, such "blind spots" will remain the primary source of losses for inattentive traders.