HypurrFi Warns Users of Suspected Domain Hijack, Urges Platform Avoidance

Apr 3, 2026, 11:33 p.m. 4 sources negative

Key takeaways:

  • Frontend compromises like HypurrFi's highlight persistent off-chain security risks, despite on-chain funds appearing safe.
  • This incident reinforces the need for investors to verify transaction details directly on-chain before signing.
  • Recurring domain hijacks across DeFi, including Curve and BONKfun, signal a systemic infrastructure vulnerability requiring user vigilance.

DeFi lending protocol HypurrFi has issued a critical security alert, warning users not to interact with its website or application following a suspected domain hijack. The protocol's founder, androolloyd, posted a direct warning on X on Friday, stating, "Do NOT USE THE HYPURR .FI domain, it is compromised."

The team clarified that while its social media accounts remain secure and under its control, the primary domain for the platform's frontend interface has been compromised. Users have been instructed to "avoid all interaction with the app until further notice from the team." The protocol, which operates on the HyperEVM blockchain and is integrated with Hyperliquid's ecosystem, currently holds approximately $30 million in Total Value Locked (TVL), according to DefiLlama.

Importantly, the team stated there is currently no evidence of risk to user funds, suggesting the issue is isolated to the frontend website and not the underlying smart contracts. However, frontend compromises pose a significant threat, as attackers can deploy malicious interfaces that mimic the legitimate app, potentially prompting users to sign transactions that drain their wallets.

This incident highlights a persistent vulnerability in the DeFi space. Domain hijacking attacks target centralized components like DNS records and web hosting, which sit outside blockchain security guarantees. Recent similar incidents include the compromise of the BONKfun domain last month and a DNS-level attack on Curve Finance in May 2025.

The immediate focus is on HypurrFi regaining control of its domain and verifying that no malicious activity occurred during the compromise. The broader takeaway reinforces the need for enhanced safeguards in domain management and the ongoing security gap between on-chain smart contracts and off-chain infrastructure.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.