
A fake HyperSwap airdrop drained approximately $12,300 from a user in just 84 seconds on June 29 at 20:21:51 UTC. According to reports from BeInCrypto, the attack began when the victim clicked a fraudulent airdrop link on X and approved a wallet request, unknowingly giving scammers control of his funds. The scammer quickly transferred NFT #178549 from the victim's wallet to their own address, controlling the liquidity position that contained 3,935 USDC and 116.6 WHYPE.
The scammer immediately withdrew the funds behind the NFT and converted the stolen assets into 175.9 HYPE tokens. As reported by BeInCrypto, the HYPE was then bridged from HyperEVM to Ethereum, with the destination wallet receiving 7.035 ETH and immediately moving the funds onward in a single transaction. The victim's position was represented by NFT #178549, which served as a digital receipt for the liquidity pool deposit and gave whoever controlled it access to the underlying funds.
The attack originated from an impostor account on X that closely resembled HyperSwap's official account, HyperSwapX. According to BeInCrypto's analysis of public blockchain records, the scammer's address (0x880C95246D7525b84902E6c040818a7C72d3Aa77) was flagged as Fake_Phishing3746335 with a 'Phish/Hack' tag by HashDit. The victim had supplied money to a HyperSwap liquidity pool and earned fees from trading against their position, making them a target for this sophisticated phishing operation.
The scammer's wallet activity suggests involvement in a larger operation, with records showing the address had been active for approximately 33 days and linked to roughly 25 other addresses. As reported by BeInCrypto, the victim attempted to report the suspicious link and get it removed but felt ignored by the HyperSwap team. The only active communication channel with HyperSwap was Discord, which was invalid at the time of reporting, leaving victims with limited recourse when fraud occurs.