HypurrFi warned users not to access its domain or app after a suspected hijack, saying social channels stay secure for now.HypurrFi warned users not to access its domain or app after a suspected hijack, saying social channels stay secure for now.

HypurrFi investigates hijack as users told to avoid app

2026/04/04 17:27
3 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

HypurrFi has warned users not to interact with its website or lending app after reporting a possible domain hijacking. 

Summary
  • HypurrFi warned users to avoid its app after reporting a possible domain compromise Friday.
  • The team said user funds remain safe while it investigates the suspected hijacking incident.
  • Frontend attacks remain a crypto risk because compromised domains can trick users into signing transactions.

The incident has raised fresh concern over frontend attacks in decentralized finance, even when onchain systems remain intact.

HypurrFi said it is investigating a possible compromise involving its domain. The team asked users to avoid the website and the lending protocol until it shares a new update.

Founder androolloyd posted on X, “Do NOT USE THE HYPURR .FI domain, it is compromised.” The team later repeated that warning and told users not to interact with the app until further notice.

HypurrFi also said there is no current sign of risk to user funds. It added that its social media accounts remain under team control during the investigation.

The warning focused on the website and user access point rather than the protocol’s core contracts. That distinction is common in cases where attackers target frontend systems instead of onchain code.

Protocol activity remains under review

HypurrFi operates as a DeFi lending and borrowing protocol on HyperEVM. HyperEVM is the EVM-compatible network linked to Hyperliquid’s trading ecosystem.

The protocol has about $30 million in total value locked, based on DefiLlama data. That made the warning more urgent for users who may still try to access the platform through the compromised domain.

The team did not provide details on how the hijacking may have happened. It also did not say when the site would return to normal use.

For now, the main message from the project remains clear. Users should avoid the domain and wait for an official notice before reconnecting wallets or signing any transaction requests.

Domain hijacking remains a known crypto risk

Domain hijacking has become a recurring issue across the crypto sector. These attacks often target a project’s website and user interface instead of its smart contracts.

Once attackers control a domain, they can place wallet drainers or other malicious prompts on the site. This method can affect users even when the underlying protocol has passed security reviews.

A similar case affected the BONKfun domain last month. That incident added to a growing list of attacks that use fake or compromised frontends to reach users.

Opportunità di mercato
Logo Notcoin
Valore Notcoin (NOT)
$0.0003773
$0.0003773$0.0003773
+10.45%
USD
Grafico dei prezzi in tempo reale di Notcoin (NOT)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!