Crypto News
A HyperSwap liquidity provider lost roughly $12,300 in 84 seconds after signing a single wallet approval that handed an attacker control of a decentralized-exchange position on the Hyperliquid blockchain. Reconstructed from public on-chain records, the case shows how fast a position can be emptied once a malicious approval is live. The victim had supplied crypto to a HyperSwap liquidity pool, earning trading fees in return. That position was tokenized as an $NFT — a digital receipt whose holder controls the underlying funds. Whoever moves the token moves the money. On-chain data shows the funds were withdrawn, converted and bridged away in under two minutes.
The trap began with a token giveaway that never existed. The victim saw a post on X promoting an airdrop and followed the link, believing he was checking eligibility for a free distribution. The account was an impostor: its handle closely mirrored the real project handle, HyperSwapX, which is linked from the official website. The lookalike name was enough to pass a quick glance. Connecting a wallet to the fraudulent site produced what looked like a routine claim step. In reality, the victim approved a transaction granting a third-party address permission to move his HyperSwap position — the single decision that decided everything.
The mechanism at work is token approval, a standard wallet action that lets another address transfer specified assets on a user’s behalf. Some approvals are harmless; others hand over valuable holdings. Here the approval covered $NFT #178549, the token representing the victim’s HyperSwap V3 liquidity position. To most users the confirmation prompt reads as ordinary, and a spoofed site can dress a dangerous approval as a normal part of claiming tokens. That is the design of modern approval phishing: the theft is authorized in advance by the victim, so no further signature is needed when the funds are actually taken.
en.coinotag.com