Alarming Hyperliquid Hack: $738,600 USDC Drained From User Account
0
0
BitcoinWorld

Alarming Hyperliquid Hack: $738,600 USDC Drained From User Account
Key Takeaways
- A Hyperliquid user account was compromised on September 9, drained of roughly 738,600 USDC, with 10,287 HYPE forcibly undelegated.
- Tracing shows the stolen stablecoins moved through Circle’s CCTP bridge and split across at least five hops before touching a Bitget-linked deposit address.
- The staked HYPE has not entered the withdrawal queue yet, meaning the theft is only partially complete.
- Two comparable cases handled recently ended the same way, pushing cumulative losses in this pattern past $1.1 million.
The Real Story Is Not the Theft. It Is the Seven Days Nobody Can Use.
Account takeovers happen weekly in crypto. What makes this one worth your attention is the part that has not happened yet.
When the attacker took control of 0x5b6d236e39a4723a8f79db93cfd1af4d228f9c60, the liquid balance went first, as it always does. The 10,287 HYPE sitting in staking is a different problem. Hyperliquid’s unstaking flow imposes a seven-day waiting period before a cWithdraw releases funds. On paper, that is a full week of warning. In practice, the victim can do absolutely nothing with it. There is no user-triggered pause, no freeze, no recovery path. The owner watches a countdown they cannot stop.

Timeline
- Compromise: Unauthorized access to the account, most likely through a leaked private key or an approved signing agent.
- Immediate drain: ~738,600 USDC transferred out.
- Undelegation: 10,287 HYPE pulled out of delegation, positioning it for withdrawal.
- Laundering: Funds routed via Circle’s CCTP bridge, then fragmented into tranches of roughly 443K, 450K, 147.5K, 147.8K and 50K across a chain of intermediary wallets.
- Off-ramp: A portion lands at an address attributed to Bitget.
- Now: HYPE remains in the staking balance, withdrawal not yet initiated.
What an Analyst Sees Here
The CCTP hop is deliberate. Native burn-and-mint transfers produce cleaner, harder-to-cluster flows than wrapped bridge assets, and the rapid fan-out into unequal amounts is textbook peel-chain behaviour designed to defeat automated tracing thresholds. The speed to a centralised exchange also tells you something: the attacker is betting on beating the compliance desk’s response window, not on sophisticated obfuscation.
The structural issue is that Hyperliquid inherits self-custody’s absolutism while offering an exchange-grade product. Ethereum’s smart accounts have had social recovery and guardian modules for years. A perps venue holding delegated stake has no equivalent.
What Comes Next
The proposal now on the table is an opt-in Guardian: a pre-configured party that can temporarily halt cWithdraw, transfers, agent approvals and multisig changes, but can never move funds. Holds expire automatically. Replacement requires a timelock and validator-governed review, recorded on-chain.
Expect pushback on censorship grounds, and expect it to be raised anyway once the fourth victim appears.
Conclusion
This is not a protocol exploit. Hyperliquid’s code did exactly what it was written to do. That is precisely the problem: a week-long delay that only benefits the thief is a design gap, not a security feature. Until account-level recovery becomes standard, every staked balance on a high-value venue is a one-key-away loss.
This post Alarming Hyperliquid Hack: $738,600 USDC Drained From User Account first appeared on BitcoinWorld.
0
0
Securely connect the portfolio you’re using to start.







