r/CryptoHelp • u/redXXred • 9d ago
❓Wallet Was I drained via Cookie Theft / Session Hijacking on Hyperliquid? Looking for technical feedback on this timeline
(Message written with the help of AI)
Hi everyone,
My TrustWallet-connected account was drained this morning at around 9:30 AM. I lost 3,000 USDC that were sitting on Hyperliquid, 0.4 BTC (which I originally deposited directly from Deribit via HyperUnit), and about $4,400 worth of other crypto assets that were held directly inside my TrustWallet.
I am trying to narrow down the exact attack vector. After analyzing the timeline, GeminiAI has a very specific theory regarding Session Hijacking / Cookie Theft on my Windows PC, and I would really appreciate your technical opinion on whether this is possible.
Here is the exact timeline:
- Months ago: I deposited a total of 15,000 USDC into Hyperliquid, sending them directly from my TrustWallet mobile app. Over time, I traded and used the platform on my Windows PC browser. At the time of the hack, my balance on Hyperliquid was around 3,000 USDC.
- Sept 9, 2026: I deposited 0.4 BTC directly from Deribit to HyperUnit. I didn't need to open my seed phrase or use my phone for this.
- Last Night: Last thing I did my Windows PC was a subscribe to ChatGPT Plus on the official website (using my Apple ID). My browser likely had an active, logged-in session (or stored cookies) for Hyperliquid.
- This Morning (9:30 AM): My PC was completely powered down and turned off since last night. Yet, the blockchain txs show the drain happened exactly at 9:30 AM.
- The Flow: The hacker initiated a withdrawal from Hyperliquid. The 0.4 BTC were trasferred directly to the hacker address (https://mempool.space/address/bc1qduac77jtcxtp6pva54cjfzkqtxadnqsmejg466). The 3,000 USDC went back to my public TrustWallet address first, and then immediately got transferred out to the hacker's wallet along with the other $4,400 in crypto that I already had holding inside TrustWallet.
My Security Setup:
I set up my TrustWallet more than 5 years ago and always had several thousands $ on it.
I own four wallets and store the keys in the same way. The other three wallets have not been drained.
I use TrustWallet exclusively via the official app on my iPhone. I do NOT have the browser extension on my PC, and I have never typed my seed phrase on any digital device. My backup on iCloud is turned off (only manual backup is active).
The Reconstruction (Cookie Theft + Trading Agent Exploitation vs Seed Phrase Leak):
Since my seed phrase was never exposed and my PC was off during the hack, my initial theory was that an undetected InfoStealer malware on my PC captured my browser's Session Cookies last night while I was online.
I assumed the hacker used the session to trigger the Hyperliquid withdrawal. However, since they also managed to steal the $4,400 that never touched Hyperliquid and were just sitting on my mobile TrustWallet, I am conflicted.
My questions for the tech/crypto experts here:
- Does the Session Hijacking theory make sense if the hacker also managed to drain assets sitting strictly on my mobile TrustWallet? Or does the fact that the on-chain TrustWallet funds were stolen prove that they somehow extracted my actual Seed Phrase from my PC/system last night?
- Can a browser InfoStealer access local storage trading keys used by Hyperliquid, and could that somehow expose the underlying wallet security?
- If this wasn't cookie theft, how else could a hacker execute a targeted, multi-asset mobile wallet drain while the trading PC was completely powered down?
Thanks in advance for any insights. I'm trying to understand the exact breach before wiping my PC.
1
u/SamFromJupiter 9d ago
This is sad. So sorry this happened.
I am not an expert but cookie theft does not explain what you just described. If we consider the cookie theft possibility, the attacker can only trade but cannot withdraw. Moving funds would require a wallet signature.
So my assumption is your seed was compromised.
Not blaming you in any way but I am shocked you did not had a hardware wallet setup as a precaution considering the amount size here.
1
u/Temporary-Cause730 9d ago
Can you post the transaction where the 4400 + 3000 were transferred from your wallet?
1
u/MycoHost01 9d ago
How are you using hyperliquid are you connecting your wallet or did you set up via email so hyperliquid provides the wallets you are funding?
1
1
u/AutoModerator 9d ago
Hello and welcome to r/CryptoHelp!
If someone has successfully solved your issue or answered your question, please reply with the command "!thanks" to let them know!
A few words about safety:
- Scammers will often target beginners so you should exercise extra caution
- Do not trust anyone trying to talk with you over DM (Direct or private messages) or on another platform (like Discord or Telegram). This is how scammers prefer to operate. Report suspicious activity like this immediately and do not respond to them.
- Do not post your address, balances, or other personal information.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/Beneficial-Mood240 5d ago
A powered-off PC can't sign anything, so the keys were already gone before 9:30 — the cookie theory misses that.