On April 4, the decentralized lending protocol HypurrFi, built on the HyperEVM infrastructure, discovered that its official domain (hypurr.fi) had been compromised. The team promptly issued a warning, stating that while user assets remain secure so far, all interaction with the application should be avoided until further notice.
Founder Confirms Breach, Urges Users to Stop Trading
HypurrFi founder Androolloyd posted on X: “The hypurr.fi domain name has been compromised. Do not interact with the platform.” He added that users should wait for confirmation through official social channels before resuming any activity. The team promised to share updates exclusively via verified accounts to prevent phishing attempts.
$30M in TVL, HyperEVM Ecosystem Under Scrutiny
According to HypurrFi’s data, the protocol holds approximately $30 million in total value locked (TVL) on HyperEVM, a high-efficiency blockchain layer optimized for perpetual trading. Although the attack did not directly touch on-chain funds, it exposed a critical vulnerability in the user interface layer. DeFi analytics firm DefiLlama notes that such breaches often cause a temporary drop in TVL, as platforms may suspend operations or escalate alerts.
Domain Hijacking Remains a Persistent Threat
Domain hijacking has become a frequent attack vector in crypto. Last month, the BONKfun platform suffered a similar incident when its domain was seized, allowing attackers to modify the homepage and trick users into fraudulent transactions. Unlike smart contract exploits, domain attacks compromise the front-end, making them harder to detect by standard audits.
Security experts recommend users verify URLs carefully, avoid clicking unsolicited links, and rely only on pinned posts from official project accounts. HypurrFi’s team stated it will maintain frequent community updates until domain access is restored. No fund losses have been reported, but the investigation remains ongoing, and additional security measures are expected to follow.

