URGENT: In the last 60 days, a hacker has compromised 1200+ addresses on Hyperliquid
The hack works with a single signature that upgrades the EOA to a 1 of 1 multisig with the hacker as the only signer
The upgrade is immediate & gives the hacker full access to all of their assets on HyperCore (including unstaking HYPE & withdrawing after 7 days)
Multsigs are a HyperCore primitive & so the hacker does not gain access to assets on HyperEVM (only HyperCore)
Putting a spreadsheet of hacked addresses in the next tweet (ty @_Syavel_ for data)

———🚨🚨URGENT🚨🚨 ——— @HyperliquidX
Requesting Immediate Help from Hyperliquid Team,
My Hyperliquid account has been compromised and was converted into a multi-sig account without my consent. The attacker added their own wallet as the sole authorized signer, effectively locking me out of my account.
all my $HYPE tokens have been unstaked, and the 7-day unstaking period has started.
As of today, there are 6 days left until the funds become withdrawable and at risk of being drained by the attacker
Here are the relevant details:
- Compromised HyperCore account: 0xeB97f37e7065A50a46f5DDEfc49e0419aBb931Bd
- Attacker's wallet (current sole authorized signer): 0x768f2ebd51176ad3783602dc86cca7c8355cdf94
- Threshold: 1
- Authorized signers: only the attacker hacker
- I still have full control over the original EVM wallet linked to the account.
I am the legitimate owner and can sign any message using my original EVM wallet to prove identity. I am requesting immediate assistance to:
- Freeze or lock the account temporarily to prevent further actions
- Remove the unauthorized multi-sig setup
- Or transfer the assets to a new wallet I control
Please let me know what proofs or verifications you need from me. I am ready to cooperate fully and provide any signatures or identity verifications required.
This is urgent, as my assets are at risk. Thank you for your understanding and prompt support.
If you're reading this and can't help directly, please push like or react to this message to help bring it to the attention of the right people on the team.
Even just one like or comment could make the difference in getting this noticed by the right people. Thank you so much.
my Discord name: ciro.hl
@chameleon_jeff @Valinorae @xulian_hl @iliensinc @HyperFND @Hyperintern @hypurr_co @HypioHL @0xHyperBeat @nansen_ai @infinitefieldx @HyperStakeX @HypurrScan @validaoxyz @asxn_r @bharvest_intern @hyperpc_ @luganodes @HyBridgeHL @PiPonHL
#HYPE #HYPERLIQUID
List of 1200+ compromised addresses:
If your address is on this list, please DM any HyperEVM apps or website you remember visiting or signing txns from so we can identify the source ASAP
If your address is on this list, your assets on HyperEVM are safe & can be transferred to a new address
The "hack" (technically a phishing signature) is only reversible with a signature from the hacker or some sort of upgrade to the multsig primitive by the Hyperliquid team/validators
It's HIGHLY recommended to separate hot & cold wallets (particular when experimenting with new apps)
In addition, you should NEVER sign signatures that are not human-readable text. When in doubt, spin up a new wallet & use that one.
deleted original tweet & reposted correct version here
[deleted & reposted to clarify it's a phishing attack, NOT a hack]
In the last 60 days, a phishing attack has compromised 1200+ addresses on Hyperliquid
The phishing attack works with a single signature that upgrades the EOA to a 1 of 1 multisig with the attacker as the only signer
The upgrade is immediate & gives the hacker full access to all of their assets on HyperCore (including unstaking HYPE & withdrawing after 7 days)
Multsigs are a HyperCore primitive & so the attacker does not gain access to assets on HyperEVM (only HyperCore)
Putting a spreadsheet of compromised addresses in the next tweet (ty @_Syavel_ for data)

360
89.07K
The content on this page is provided by third parties. Unless otherwise stated, OKX is not the author of the cited article(s) and does not claim any copyright in the materials. The content is provided for informational purposes only and does not represent the views of OKX. It is not intended to be an endorsement of any kind and should not be considered investment advice or a solicitation to buy or sell digital assets. To the extent generative AI is utilized to provide summaries or other information, such AI generated content may be inaccurate or inconsistent. Please read the linked article for more details and information. OKX is not responsible for content hosted on third party sites. Digital asset holdings, including stablecoins and NFTs, involve a high degree of risk and can fluctuate greatly. You should carefully consider whether trading or holding digital assets is suitable for you in light of your financial condition.