Skip to main content
AVOID.NET

Fake Hyperliquid App

avoid.net/fake-hyperliquid-app0/100·100% conf.

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·2sK5CJ…7BWm

Summary

A fraudulent mobile application impersonating Hyperliquid, the decentralized perpetuals exchange, was identified on the Google Play Store in November 2025 by on-chain investigator ZachXBT. The app, published under the developer name 'Tvtion Inc.', replicated Hyperliquid's branding and interface to harvest users' seed phrases, transmitting them to an external server. An Ethereum address linked to the operation has been associated with thefts exceeding $281,000; Hyperliquid has never released an official mobile application, making any such listing inherently fraudulent.

Connected Entities

5 entities · 60 linked investigations
Organizations
Protocols
Relationships
  • Fake Hyperliquid Appmentioned withHyperliquid(70%)
  • Fake Hyperliquid Appmentioned withZachXBT(70%)
  • Fake Hyperliquid Appmentioned withSushiSwap(65%)
  • Fake Hyperliquid Appmentioned withEthereum(70%)
  • ZachXBTmentioned withEthereum(70%)
  • Hyperliquidmentioned withEthereum(70%)
  • SushiSwapmentioned withEthereum(60%)
  • SushiSwapmentioned withZachXBT(65%)
Have evidence about Fake Hyperliquid App?

Timeline(4 events)

June 2025

Cybersecurity firm Cyble Research and Intelligence Labs (CRIL) identifies over 20 malicious crypto applications on the Google Play Store impersonating platforms including Hyperliquid, SushiSwap, and PancakeSwap, all using seed-phrase harvesting techniques.

CoinEdition / Cyble CRIL report

26 June 2025

A separate Google Ads phishing campaign targeting Hyperliquid users is reported, in which fraudulent ads for HypurrScan (hypurrscan.net) redirect users to a fake Cloudflare CAPTCHA page designed to execute malicious commands on Windows machines.

The Coin Republic

7 November 2025

ZachXBT publishes a warning via his Telegram investigations channel (post 287) about a fake Hyperliquid application on the Google Play Store published by developer 'Tvtion Inc.', identifying Ethereum theft address 0x8c12C21C394D9174c3b1a086A97d2C5523ABb8F5. The post receives over 126,000 views.

ZachXBT Investigations Telegram / Phemex News

8 November 2025

Multiple crypto news outlets including CoinEdition, CryptoTimes, and CryptoRank cover ZachXBT's warning, reporting the theft address has been linked to losses exceeding $281,000 and that a parallel Apple App Store variant resulted in approximately $28,000 stolen from two users.

CryptoTimes / CryptoRank / CoinEdition
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (4 events).

Fact-checked 2026-09-0918 claims checked9 corrections pending0 applied⛓ anchoredSee findings →

model: claude-sonnet

generated: 5/4/2026, 4:05:06 PM

last updated: 6/13/2026, 6:18:49 PM

15 views

avoid.net — verified advice for a post-truth world