EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Shocking Hyperliquid hack: User account $738,600 USDC stolen

2026-09-10 00:30:53
Bookmark

Shocking Hyperliquid hack incident: US$738,600 USDC stolen from user accounts

Core points

  • On September 9, a Hyperliquid user account was compromised and approximately 738,600 USDC were stolen, while 10,287 HYPEs were forcibly depledged.
  • On-chain tracking shows that the stolen stablecoins were transferred through Circle's CCTP bridging protocol, and after at least five transfers, they finally entered the recharge address associated with Bitget.
  • The pledged HYPE has not yet entered the withdrawal queue, which means that the theft is only partially completed.
  • Two similar cases handled recently have the same outcome, and the cumulative losses caused by such tactics have exceeded US$1.1 million.

The truth lies not in the theft itself, but in the seven-day dilemma of being unavailable.

Account takeovers in the cryptocurrency space occur every week. But what deserves attention in this incident is not the theft itself, but the subsequent impact that has not yet occurred.

When an attacker controls the address 0x5b6d236e39a4723a8f79db93cfd1af4d 228f9 c60When the current balance is cleared, the current balance is first cleared, which is a normal operation for such events. However, the 10,287 HYPEs stored in pledge pose another problem. Hyperliquid's release process requires a seven-day wait before releasing funds. On paper, this is a full-week warning period; but in practice, there is nothing the victim can do about it. There is no user-triggered pause mechanism, no freezing function, and no recovery path. The owner could only watch as the countdown progressed but could not stop it.

事件相关图表

Timeline

  • Account intrusion: Unauthorized access to the account may be due to a leaked private key or an approved signing agent.
  • Immediate theft: About 738,600 USDC were transferred out.
  • Cancel commission: 10,287 HYPEs are extracted from the commission status to prepare for withdrawal.
  • Fund laundering: Funds are routed through Circle's CCTP bridge and then dispersed into a series of intermediate wallets with amounts of approximately US$443,000, US$450,000, US$147,500, and US$50,000 respectively.
  • Fiat conversion: Some of the funds flowed into an address attributed to Bitget.
  • Current status: HYPE is still retained in the pledge balance, and withdrawal has not yet been started.

Analyst Perspective

The transfer of CCTP was deliberate. Native destruction and casting transfers produce cleaner and more difficult to cluster flows than packaging bridges assets, and rapid dispersion into unequal amounts is a typical "peel-chain" technique designed to circumvent automatic tracking thresholds. Rapid entry into a centralized exchange also reveals a message: attackers are betting on beating the response window of compliance departments rather than relying on complex obfuscation techniques.

The structural problem is that Hyperliquid inherits the absolutism of self-custody while offering exchange-level products. Ethereum's smart accounts have had social recovery and guardian modules for many years, but perpetual contract platforms that hold entrusted pledges do not have a similar equivalent mechanism.

Future Outlook

The solution currently proposed is an optional Guardian mechanism: a pre-configured third party that can temporarily suspend withdrawal requests, transfers, agent approvals, and multi-signature changes, but never move funds. Freeze automatically expires. Replacement requires a time lock and review by the verifier and is recorded on the chain.

is expected to face objections to censorship, and such objections will be raised anyway once a fourth victim appears.

Conclusion

This is not a protocol loophole. Hyperliquid's code runs exactly according to the logic it was written. And that's the problem: a week-long delay only benefits thieves, which is a design flaw, not a security feature. Before account-level restoration became the standard, every pledge balance in high-value locations was at risk of "losing the key".

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP