The Hyperliquid ecosystem, despite its popularity, continues to demonstrate serious security gaps that are actively exploited by attackers. A user contacted my editorial office who lost approximately $12,000 on the decentralized exchange HyperSwap, operating on the HyperEVM network. The incident is a classic example of a phishing attack, where the victim themselves, due to inattention, granted scammers access to their funds.
How it all began: a substitution that went unnoticed
The victim held assets in the HyperSwap liquidity pool. The right to a share in the pool was confirmed by a unique NFT. It all started when the user saw a post on social network X (formerly Twitter) from an account they believed was the official HyperSwap. The post offered an airdrop. By clicking the link, they landed on a clone website, where they were asked to "verify eligibility" for free tokens. In reality, the link hid a drainer—a malicious tool for stealing funds from a crypto wallet.
Key point: the scammers' account was a duplicate of the official one, differing by just a couple of letters. The user did not notice the substitution. On the clone website, they connected their wallet and confirmed a transaction, thinking they were simply checking eligibility for the drop. By this action, they granted the scammer permission to manage their investment. Externally, such a confirmation request is no different from regular operations on legitimate services, which is what makes this type of attack so dangerous.
Theft in two minutes: timeline of events
The active phase of the theft occurred between 20:21 and 20:23 UTC on June 29, 2026. The fraudulent address, flagged by the security service HashDit as Fake_Phishing3746335, using previously obtained access, transferred the NFT with the user's investment to its own wallet. Importantly: this operation was initiated and the fee paid by the scammer themselves—the victim did not sign anything at that moment. This is the essence of a drainer: access is obtained in advance, and the withdrawal of funds happens later, without the owner's involvement.
Then, the attacker withdrew liquidity from the stolen NFT: approximately 3935 USDC and 116 WHYPE, totaling around $12,100. Next, using the legitimate cross-chain bridge service LI.FI, they converted all funds into HYPE and withdrew about $12,300 from the HyperEVM network to the Ethereum network. Using a legitimate service for the withdrawal is a typical technique that complicates tracking and creates a false impression for the victim that the service or exchange itself is to blame.
Team response: ignoring the problem
Upon discovering the loss, the user tried to contact the project team to have the fraudulent link removed. However, the link remained active since June 26. They also attempted to alert the Hyperliquid team via Discord and GitHub, but there was no response. The only active communication channel with HyperSwap—Discord—was invalid at the time of the incident. The victim reasonably assumed that HyperSwap employees might be involved in the theft or deliberately concealing it, given the complete disregard for the problem.
Expert comment: This case is not an isolated instance of negligence but a systemic problem within the Hyperliquid ecosystem. The fraudulent address was active for about a month and linked to approximately 25 different wallets. This indicates a well-established, streamlined scheme. As long as the Hyperliquid team and its satellites like HyperSwap do not start responding promptly to such threats and cleaning up phishing links, the ecosystem will remain a "blind spot" for its own users' security. Decentralization should not be synonymous with irresponsibility.