Protocol-impersonator domain registered (typosquat)
Hyperliquid's assessment for RD-F-161 — scored red on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
CONFIRMED ACTIVE IMPERSONATION CAMPAIGN. Multiple impersonator domains documented and confirmed active: claim-hyperliquid[.]xyz (wallet-draining fake airdrop site, PCRisk removal guide 2024-2025), hyperliquid[.]life (closely mimicking hyperliquid.xyz, PCRisk documented), fake Google Ads campaigns serving malicious sites for 'Hyperliquid' search term (Phemex reporting), and multiple removal guides published by anti-malware firms (PCRisk, EnigmaSoftware) indicating a sustained campaign. Official domain: hyperliquid.xyz and app.hyperliquid.xyz. Registration dates within last 90 days not confirmed via WHOIS (DomainTools API not available in OSINT scope — structural data gap), but ongoing active campaigns with live scam activity are sufficient to score red at curator confidence. The HYPE token launch (November 2024) created sustained incentive for fake airdrop domains that remains active.
Sources #
- URLhttps://www.pcrisk.com/removal-guides/29899-hyperliquid-hype-airdrop-scamretrieved 2026-04-28
- https://www.enigmasoftware.com/hyperliquidhype-removal/retrieved 2026-04-28
Methodology #
Determine whether a typosquat of the official protocol domain has been registered in the last 90 days.
See the full factor methodology and distribution across all protocols →