The tweet was deleted by the author.
But we saved everything 🙂.
Hyperdrive, a decentralized DeFi yield strategy protocol built on the Hyperliquid ecosystem, has confirmed a security incident that compromised two wallet positions in its Treasury Market, resulting in estimated losses of between $700,000 and $773,000.
The event, disclosed on September 27, 2025, prompted the team to temporarily suspend all money markets on the platform as a precautionary measure while launching a comprehensive investigation.
According to official statements, the exploit was linked to a flaw in the operator permission system, which attackers used to leverage the protocol’s Router and execute arbitrary calls to whitelisted contracts, allowing them to drain targeted positions. Hyperdrive clarified that no vulnerabilities were found in the thBILL token or the HYPE governance token. The team stressed that the issue was isolated and did not affect the broader ecosystem.
In the latest update posted on X (formerly Twitter), the project reported that it had identified and fixed the root cause, verified the affected accounts, and is now preparing a compensation plan. Normal market operations are expected to resume within 24 hours. The team also warned users about phishing attacks, urging them to trust only official communications and avoid interacting with the protocol until full functionality is restored.
The Hyperdrive incident occurred just one day after a $3.6 million rug pull at HyperVault, another protocol built on Hyperliquid. The stolen funds were moved from Hyperliquid to Ethereum, converted into ETH, and sent through Tornado Cash, a common money-laundering tool in crypto exploits. The sequence of events has reignited concerns over the security resilience of the Hyperliquid network, which operates with only four validator nodes, potentially increasing the risk of coordinated attacks.
Despite these challenges, market stability among major cryptocurrencies remains intact. Hyperdrive’s audits, formal verification, and fuzz testing have not identified any systemic vulnerabilities. Analysts believe that transparency and swift response could help restore user confidence, as seen in similar DeFi cases in the past.
While regulators have not yet intervened, the rapid succession of breaches has caused concern among investors, with reports indicating over $200 million in USDC withdrawals within 24 hours. Nevertheless, Hyperdrive’s proactive measures—including market suspension, vulnerability mitigation, and a compensation plan—have helped prevent further losses.
Observers suggest that this response could serve as a positive example of crisis management in the DeFi sector. If the team maintains transparent communication and follows through on its recovery plan, community trust could rebound, positioning Hyperdrive as a model for responsible incident response amid growing industry scrutiny.
Read also: Political risks and ETF outflows weigh on Bitcoin and Ethereum