Fact-check findings
What an automated fact-checker found when it re-read Fake Hyperliquid App against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
6 claimsThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #1[disputed][awaiting moderator]in section: Overview and Discovery
“On November 7, 2025, on-chain investigator ZachXBT published a warning via his Telegram channel (t.me/investigations, post 287) alerting the crypto community to a fraudulent Hyperliquid application available on the Google Play Store.”
reviewerZachXBT's warning about the fake Hyperliquid app was published as Telegram post number 287 on t.me/investigations.The page's own citation (t.me/s/investigations/288) contradicts its prose, which twice says 'post 287.' A live fetch of post 287 shows a different, unrelated warning, and an independent search explicitly identifies post 288 as the Hyperliquid Google Play alert. The date (Nov 7, 2025) and platform (Google Play) are otherwise well corroborated.Proposed correction (not yet applied)On November 7, 2025, on-chain investigator ZachXBT published a warning via his Telegram channel (t.me/investigations, post 288) alerting the crypto community to a fraudulent Hyperliquid application available on the Google Play Store. - #2[disputed][awaiting moderator]in the timeline
“ZachXBT publishes a warning via his Telegram investigations channel (post 287) about a fake Hyperliquid application on the Google Play Store published by developer 'Tvtion Inc.', identifying Ethereum theft address 0x8c12C21C394D9174c3b1a086A97d2C5523ABb8F5. The post receives over 126,000 views.”
reviewerZachXBT's warning about the fake Hyperliquid app was published as Telegram post number 287.Same post-number error as in the Overview section, repeated in the timeline event text.Proposed correction (not yet applied)ZachXBT publishes a warning via his Telegram investigations channel (post 288) about a fake Hyperliquid application on the Google Play Store published by developer 'Tvtion Inc.', identifying Ethereum theft address 0x8c12C21C394D9174c3b1a086A97d2C5523ABb8F5. The post receives over 126,000 views. - #4[disputed][awaiting moderator]in section: Overview and Discovery
“ZachXBT noted that major app platforms 'don't do a good job of filtering these scams out.'”
reviewerZachXBT's exact quoted words were 'don't do a good job of filtering these scams out.'The page presents this as a direct quotation, but the verbatim ZachXBT quote (confirmed by CryptoTimes and used correctly elsewhere on the same page, in the Platform Security Failures section) is 'None of these platforms seem to do a good job of filtering these scams out.' The Overview section's wording matches a third-party paraphrase, not ZachXBT's actual words.Proposed correction (not yet applied)ZachXBT noted that major app platforms, in his words, 'none of these platforms seem to do a good job of filtering these scams out.' - #15[disputed][awaiting moderator]in the timeline
“A separate Google Ads phishing campaign targeting Hyperliquid users is reported, in which fraudulent ads for HypurrScan (hypurrscan.net) redirect users to a fake Cloudflare CAPTCHA page designed to execute malicious commands on Windows machines.”
reviewerThe Google Ads/HypurrScan Cloudflare-CAPTCHA phishing campaign was reported on 2025-06-26 by The Coin Republic.The timeline entry's description belongs to a different, later article (SecDesk, published July 6, 2025) than the one it cites and dates (The Coin Republic, June 26, 2025), which covers an unrelated Hyperliquid phishing incident with a different domain and technique. The June 26 Coin Republic campaign itself is real but is not otherwise represented on the page.Proposed correction (not yet applied)https://secdesk.com/phishing-gets-hyperliquid-when-google-ads-serve-the-payload/ - #16[disputed][awaiting moderator]in the timeline
“2025-06-26”
reviewerThe Google Ads/HypurrScan Cloudflare-CAPTCHA phishing campaign occurred/was reported on 2025-06-26.Date should track the source that actually reports the described campaign.Proposed correction (not yet applied)2025-07-06 - #17[disputed][awaiting moderator]in the timeline
“The Coin Republic”
reviewerThe Google Ads/HypurrScan Cloudflare-CAPTCHA phishing campaign was reported by 'The Coin Republic.'Publisher attribution should match the corrected source_url.Proposed correction (not yet applied)SecDesk
unverifiable
1 claimNo source the reviewer could reach confirms or contradicts the claim.
- #3[unverifiable][awaiting moderator]in section: Overview and Discovery
“The post received over 126,000 views.”
reviewerThe 'over 126,000 views' figure for ZachXBT's Telegram post is accurate.Plausible but not independently confirmable to the specific figure; no contemporaneous (November 2025) source with this exact number was found.
stale
3 claimsThe claim was accurate when written but events since have overtaken it.
- #5[stale][awaiting moderator]in the summary
“An Ethereum address linked to the operation has been associated with thefts exceeding $281,000; Hyperliquid has never released an official mobile application, making any such listing inherently fraudulent.”
reviewerHyperliquid has never released an official mobile application.True as of the November 2025 incident, but Hyperliquid has since shipped an official Android app (MVP, notifications-only), so the blanket present-tense claim is now stale.Proposed correction (not yet applied)An Ethereum address linked to the operation has been associated with thefts exceeding $281,000; at the time of the incident, Hyperliquid had never released an official mobile application, making any such listing inherently fraudulent, though Hyperliquid released an official Android MVP app in April 2026. - #6[stale][awaiting moderator]in section: Overview and Discovery
“Hyperliquid, the decentralized perpetuals exchange operating primarily on its own Layer 1 blockchain, has never released an official mobile application for Android or iOS, meaning any such listing on app marketplaces is fraudulent by definition.”
reviewerHyperliquid has never released an official mobile application for Android or iOS.Same underlying staleness as the summary claim.Proposed correction (not yet applied)Hyperliquid, the decentralized perpetuals exchange operating primarily on its own Layer 1 blockchain, had never released an official mobile application for Android or iOS at the time, meaning any such listing on app marketplaces was fraudulent by definition; Hyperliquid released an official Android MVP app in April 2026, though no iOS app has been released. - #7[stale][awaiting moderator]in section: Platform Security Failures
“The fake Hyperliquid app was able to pass Google Play's review process despite Hyperliquid having no official mobile application, making the listing straightforwardly impersonating.”
reviewerHyperliquid has no official mobile application.Third occurrence of the same now-stale claim.Proposed correction (not yet applied)The fake Hyperliquid app was able to pass Google Play's review process despite Hyperliquid having no official mobile application at the time, making the listing straightforwardly impersonating; Hyperliquid released an official Android MVP app in April 2026.
confirmed
8 claimsThe cited evidence supports the claim as written.
- #8[confirmed][no action needed]in section: Developer and App Store Listing
“The fraudulent application was published on the Google Play Store under the developer name 'Tvtion Inc.'”
reviewerThe fraudulent app was published under the developer name 'Tvtion Inc.'Developer name corroborated across multiple independent outlets. - #9[confirmed][no action needed]in section: Developer and App Store Listing
“The app replicated Hyperliquid's official logo, app description, and user interface design with high fidelity, and allegedly included fabricated positive reviews to increase its credibility in the store listing.”
reviewerThe app replicated Hyperliquid's logo, description, and UI, and included fabricated positive reviews.Consistent with independent reporting; the page appropriately hedges with 'allegedly' on the fake-reviews detail. - #10[confirmed][no action needed]in section: Developer and App Store Listing
“A separate but related fake Hyperliquid application was also alleged to have appeared on Apple's App Store, where two users reportedly lost approximately $28,000.”
reviewerA separate fake Hyperliquid app on Apple's App Store resulted in two users losing approximately $28,000 combined.Directly confirmed by CryptoTimes. - #11[confirmed][no action needed]in section: Phishing Mechanism and Drainer Operation
“The fraudulent application presented users with a login screen prompting them to either 'connect wallet' or 'restore account.'”
reviewerThe app's login screen prompted users to 'connect wallet' or 'restore account,' and the entered seed phrase/private key was exfiltrated to an attacker-controlled server, giving full control over the wallet across all chains.Mechanism description is consistent across independent reports and is technically coherent (seed-phrase phishing vs. on-chain drainer approval). - #12[confirmed][no action needed]in section: On-Chain Theft Address and Financial Impact
“Multiple outlets reporting on the investigation noted this address had been associated with thefts exceeding $281,000 at the time of the warning.”
reviewerEthereum address 0x8c12C21C394D9174c3b1a086A97d2C5523ABb8F5 has been linked to thefts exceeding $281,000.The $281,000 figure is repeated across several secondary outlets tracing back to ZachXBT's original post; no primary on-chain analytics report with that exact figure was located, which the page itself candidly discloses. The hedge already in the page text is accurate and should be kept. - #13[confirmed][no action needed]in section: Broader Campaign Context
“Cybersecurity firm Cyble Research and Intelligence Labs (CRIL) identified over 20 malicious crypto-related apps on the Google Play Store in 2025, impersonating platforms including SushiSwap, PancakeSwap, and Hyperliquid, all using the same seed-phrase harvesting approach.”
reviewerCyble Research and Intelligence Labs (CRIL) identified over 20 malicious crypto apps on Google Play in 2025 impersonating SushiSwap, PancakeSwap, and Hyperliquid.Well supported by the cited source and independently corroborated. - #14[confirmed][no action needed]in section: Broader Campaign Context
“The Google Ads phishing vector involved a spoofed domain (hypurrscan.net impersonating hypurrscan.io) that presented a fake Cloudflare CAPTCHA page designed to trick Windows users into executing a malicious command via the Run dialog.”
reviewerA Google Ads phishing campaign used a spoofed domain (hypurrscan.net impersonating hypurrscan.io) with a fake Cloudflare CAPTCHA page tricking Windows users into executing a malicious command via the Run dialog.Accurately described and correctly cited within this section; the problem is only in the timeline entry for this event (see separate finding). - #18[confirmed][no action needed]in section: Platform Security Failures
“ZachXBT's warning explicitly criticized app store platform moderation, stating that 'none of these platforms seem to do a good job of filtering these scams out.'”
reviewerZachXBT's exact quote criticizing platform moderation was 'none of these platforms seem to do a good job of filtering these scams out.'This is the accurate rendering of the quote; contrast with the Overview section's inaccurate version flagged separately.