The case of stolen funds on HyperSwap once again showed why Hyperliquid security remains a painful topic for ecosystem users: a single click on a phishing link in X ended with the loss of about $12,000, and the asset withdrawal itself took less than two minutes.
An investor who held funds on the decentralized exchange HyperSwap on the HyperEVM network contacted the BeInCrypto editorial office. According to him, he followed a link from the X social network, connected his wallet to a site promising an airdrop, and ultimately gave scammers access to his position.
According to the blockchain explorer, the scheme looked like a classic drainer: first, the user was tricked into granting permission, and later the attacker initiated transactions themselves and took the assets without new confirmations from the wallet owner.
How the User Ended Up on a Phishing Site
The victim was placing assets on HyperSwap. On this platform, the user deposits coins into a common liquidity pool and receives income, with their share confirmed by an NFT with a unique number. For the owner, such an NFT was not just a token, but an asset that gave the right to the invested funds.
In X, he saw a post with a link to a page where supposedly you could check your eligibility for free coins. The site turned out to be a fake, and behind the wallet connection form was a drainer—a tool that helps scammers take funds after obtaining the necessary permissions.
HyperSwap operates on the Hyperliquid blockchain, specifically on its HyperEVM layer. At the same time, HyperSwap has a separate team: Hyperliquid does not manage this exchange directly, just as Ethereum does not control the applications that run on top of its network, such as Uniswap.
The Impersonator Account Looked Almost Real
The key trick was substitution. The link was posted not by the official HyperSwap account, but by a fake page with a very similar name. The difference came down to a few characters, so it was easy to miss when quickly scrolling through the feed.
Scammers often count on this scenario: the impersonator account and clone site look convincing enough, and a single careless wallet signature can cost the user all their funds.
On the fake site, the victim connected their wallet and confirmed the operation, thinking they were checking airdrop participation. In practice, this action gave the attacker the right to manage their investment. Outwardly, such requests may resemble ordinary operations on legitimate services, so the trick often becomes obvious only after the deduction.
It is important not to confuse this episode with market mechanisms: it was not related to market liquidity, oracles, regulation, or liquidation. This is user risk and a typical vulnerability (computer security), when the wallet owner themselves, not understanding the consequences, grants a dangerous permission.
The Theft Took Less Than Two Minutes
The active phase of the attack took place on June 29, 2026, between 20:21 and 20:23 UTC. The hyperevmscan explorer marked the attacker’s address as Fake_Phishing3746335 based on a signal from the HashDit security service.
First, this address used the previously obtained access and transferred the NFT with the user’s position to its own wallet. An important detail: the transaction was initiated by the scammer themselves, who also paid the fee. At the time of the theft, the victim was no longer signing anything.
After this, the attacker withdrew the invested coins from the NFT: about 3,935 USDC and 116 WHYPE. The total loss amounted to about $12,100. Then, through a legal exchange and transfer service, the stolen funds were converted to HYPE, after which about $12,300 was sent from HyperEVM to the Ethereum network.
How the Attacker Covered Their Tracks
In Ethereum, the money arrived at an address created shortly before the transfer. It was used essentially once: it received the funds, almost immediately sent them further in a single transaction, and remained almost empty. Such one-time transit wallets are often found in chains of stolen asset withdrawals.
Additional confusion is created by the fact that the scammer did not use any obviously criminal tool. To move the funds, they used a regular legal inter-network transfer service. Because of this, the victim may feel that the problem is with the service or exchange, although the theft itself began with phishing permission.
According to the explorer, the fraudulent address was active for about a month and linked to about 25 different wallets. This looks more like an established scheme than an isolated case.
The Victim Tried to Warn Project Teams
After the funds disappeared, the user tried to get the dangerous link removed. According to him, the link to the phishing resource continued to remain in the messages.
The victim claims that he tried various ways to warn the Hyperliquid team about the scam but received no response. In one of the screenshots, you can see how he contacts Hyperliquid support via Discord, asking them to pass on information about the discovered threat, and in response, he is advised to contact HyperSwap himself.
According to the user, the only active communication channel with HyperSwap remained Discord, but at the time of preparing the material, the link to it was already not working. Therefore, he tried to convey the problem through the ecosystem team in which the project operates, but this also did not help.
The victim also suggested that HyperSwap employees might be involved in the theft or deliberately hiding what was happening. There is no evidence for this version in the provided data, but the very fact of the lack of a clear response to complaints increased his suspicions.
How to Reduce Phishing Risk in a Crypto Wallet
- Open exchanges and services only via addresses from official sources: do not follow links from posts, comments, or private messages on social networks.
- Check the account name letter by letter: scammers often create copies of pages that differ from the real ones by only one or two letters.
- Do not confirm wallet operations if you do not understand their meaning: be especially careful with permissions to manage tokens, NFTs, and positions in pools.
- Regularly check granted permissions and revoke unnecessary ones: use reliable services and enter their addresses manually.
- If you suspect hacking or phishing, immediately revoke all permissions and transfer assets: it is better to send the remaining funds to a new address.
The main conclusion is simple: a drainer does not always need to hack the protocol. Sometimes it is enough to convince the user to sign a single dangerous request, and then calmly withdraw assets without their participation.
{
“@context”: “https://schema.org”,
“@type”: “Article”,
“about”: [
{
“@type”: “Organization”,
“name”: “Hyperliquid”
},
{
“@type”: “Organization”,
“name”: “Ethereum”
},
{
“@type”: “Thing”,
“name”: “blockchain”
},
{
“@type”: “Thing”,
“name”: “vulnerability”
},
{
“@type”: “Thing”,
“name”: “risk”
},
{
“@type”: “Thing”,
“name”: “asset”
}
]
}




