Hyperdrive HL Hack

TOTAL LOST $782K
Low Access Control Attacks hyperliquid l1

What happened

On September 28, 2025, Hyperdrive, a lending protocol on the Hyperliquid blockchain, lost approximately $782,000 after an attacker exploited a smart contract vulnerability. The breach targeted two key liquidity pools, draining 673,000 USDT0 and 110,244 thBILL tokens, marking the third major security incident on the Hyperliquid ecosystem in 2025.

The attacker exploited an "arbitrary call in the router" vulnerability within Hyperdrive's smart contract system, allowing unauthorized access to funds from the Primary USDT0 Market and Treasury USDT Market pools. Through repeated exploitation of this flaw, the attacker drained 672,934 USDT0 stablecoins and 110,244 thBILL tokens. The stolen assets were subsequently converted to BNB and ETH before being moved off-chain.

Hyperdrive immediately paused all markets and suspended withdrawals to prevent further malicious activity while working with security and forensics experts to investigate. The team confirmed the root cause has been identified and resolved, and is developing a compensation plan for affected users along with a comprehensive postmortem report.

Case & protocol details

Classification Protocol Logic / Borrowing and Lending / Access Control
Protocol Type Lending
Smart Contract Language Solidity
Official Website hyperdrive.fi/
Protocol Twitter/X @hyperdrivedefi

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.