CryptoReal
CASE FILE — Sep 30, 2025

How a Fabricated Audit Trail Masked HyperVault's $4.64 Million HyperEVM Exit Scam

HyperVault pitched itself as a non-custodial, auto-compounding yield aggregator built on Hyperliquid's HyperEVM, promising returns as high as 95% APY through what it called "modular strategy adapters" and "keeper-bot harvests." On September 25-26, 2025, the protocol confirmed it was a rug pull: roughly $4.64 million was drained from nine vaults, bridged to Ethereum through deBridge, and laundered through Tornado Cash while the team's social media accounts, Discord server, and website disappeared.

01A protocol built on invented credentials

Underneath the marketing language, HyperVault ran on an internal ledger rather than standard vault-share tokens, gave itself privileged contract functions disguised as routine safeguards, and claimed relationships with audit firms that, when contacted, said they had never heard of the project. It advertised up to 95% APY on some assets and 76% on stablecoin deposits — numbers well outside what legitimate DeFi yields typically support.

Roughly 1,100 depositors put funds in despite multiple visible red flags: unverifiable audit claims, an anonymous team, and yields that made little economic sense. The public face of the project was a person going by Nick Olsen, who claimed to be based in Sweden, while a wider group of developers — later shown to have prior involvement in other suspicious projects — built the supporting code.

02The warning nobody heeded

The first public alarm came on September 4, 2025, when a Hyperliquid community member known as HypingBull posted that HyperVault was "doing shady stuff." At the time, the project claimed audits were pending from Spearbit, Pashov, and Code4rena, with results expected by mid-September.

HypingBull followed up by messaging Pashov directly on Telegram to check the claim. The response: "First time I hear the project with this name." A check of Code4rena's public audit queue turned up nothing related to HyperVault either — no pending, active, or scheduled engagement. Total value locked in the protocol at that point stood at roughly $700,000. HypingBull withdrew all funds and urged others to do the same; most depositors stayed in.

Despite the warning, HyperVault's reported TVL kept climbing, reaching an estimated $5.8 million according to later tracking — a figure some observers considered inflated but still representing real deposits. DefiLlama data put TVL at $4.97 million on September 24, then at zero the following day.

On September 23, HYPEconomist — described as a prominent Hyperliquid community voice — publicly endorsed the protocol: "cooking! use the money and put it into a hypervault." The rug followed three days later. Afterward, community members criticized the endorsement as shilling; HYPEconomist responded that "they rugged me too."

03A real audit, buried

The most striking element of the case is that HyperVault did commission a genuine security review — and then suppressed it. On September 14, the project announced on X that it was "starting" an audit with the firm Zenith. Zenith did carry out the work, and delivered a draft report privately on September 24 identifying 42 vulnerabilities in total — six rated High severity, ten rated Medium — along with a recommendation that the protocol undergo a full re-audit once fixes were made.

HyperVault acknowledged the findings privately but said nothing publicly, and the rug occurred two days later. The draft audit was never published, leaving depositors unaware that a protocol they were trusting with their funds carried multiple critical unresolved issues. After the collapse, Zenith said it would cooperate with investigators and noted that DocuSign metadata tied to the audit engagement contained an IP address linked to Nicholas Olsen.

Integration partner Hybra Finance was caught up in the fallout: it had quote-retweeted a HyperVault announcement after seeing Zenith's name attached — based only on the fact that an audit process had begun, not that it had concluded favorably. Following the rug, Hybra acknowledged the misstep — "We clearly did not do enough DD" — and offered full reimbursement to users who interacted with HyperVault after September 25 at 3PM UTC (the time Hybra had amplified the post) and who had prior on-chain history with Hybra, plus a smaller goodwill allocation for other affected HyperVault users at Hybra's eventual launch.

04How the extraction worked

Standard DeFi vaults typically issue ERC-4626 share tokens that let depositors verify their holdings on-chain. HyperVault instead used an internal ledger and a global accrual index, issuing no share tokens at all. The design was described by the team as "gas-efficient," but it also meant outside observers had no easy way to track who owned what — balance changes were invisible unless someone queried the contract directly.

Buried in the contract was a privileged function gated by an onlyHV() modifier, presented as a safety mechanism but functioning as an administrative override. On September 25, the contract owner reassigned the staking contract to their own externally-owned account and triggered mass withdrawals across all nine vaults.

Four days prior, the HyperVault developer had funded five addresses from Hypercore to HyperEVM via spotSend, covering gas costs in $HYPE. Only two of those five addresses were ultimately used to carry out the extraction:

Sums referenced in this case file

Extracted tokens were swapped into $HYPE and bridged to Ethereum via deBridge in multiple batches:

On Ethereum, the funds were split across four wallets:

Over the following three to four days, nearly all of the 1,126 ETH moved into Tornado Cash across multiple deposits from these four addresses, leaving only gas-fee dust behind. SpecterAnalyst's on-chain analysis traced the exploitation addresses and confirmed the total at $4.64 million — close to the $4.97 million TVL DefiLlama had reported just before the rug. SpecterAnalyst further traced the Tornado Cash withdrawals to a set of destination wallets:

By the time anyone noticed the fund movements, the extraction was already finished. Social media accounts were deleted, the Discord server removed, the website taken offline, and documentation erased. Because the proceeds passed through Tornado Cash, conventional legal recovery is effectively ruled out.

05The people behind the project

The public face of HyperVault, going by Nick Olsen and claiming Swedish residency, used the Twitter/X handle 0xNyck, which remained active even after the rug. His Discord username was "0xnyck | hypervault.fi," though he had joined the project's own Discord server only in September 2025 despite claims that development had been underway since late July. A business-development email tied to the project was [email protected]. Several community members, including HYPEconomist, said they had video calls with Olsen before depositing — a degree of apparent transparency that ultimately did not prevent the loss of $4.64 million.

Investigator BrutalTrade published a set of email addresses tied to GitHub accounts associated with the developer network:

When confronted on Telegram after the collapse, several of these developers began deleting repositories and accounts rather than responding. Jamestarlancer removed his entire GitHub account within minutes of being named, and gurujustin deleted the zerog-ui repository before deleting the account itself.

BrutalTrade linked the same network to earlier projects — Zero-G Finance, PerfectSwap, and NodeSynapse — and found that domains for all of them were registered through Njalla, a registrar known for anonymizing ownership: hypervault.finance, zino.finance, zerog.finance, perfectswap.io, and seadrome.finance.

Tracing wallet activity further, BrutalTrade identified a Binance deposit address that had received funds from wallets tied to the scam:

On September 28, BrutalTrade sent a message to addresses linked to the team offering to let them keep 10% of the funds as a bounty and halt legal action if the rest were returned within 24 hours — sent to five addresses tied to the operation as well as a wallet previously used during ZinoFinance's development. There was no response. BrutalTrade's later update noted that the team's code repositories, commits, and history had all been archived before deletion: "We git cloned everything ;)" A Telegram channel was opened for the community to continue tracking efforts.

06Innocent parties drawn into the trace

The on-chain investigation also swept up parties with no connection to the scam. Blockchain analysis showed that Kupia Security, a legitimate audit firm, had a wallet (kupia.eth) that once sent $25 to the same Binance deposit address later used by the HyperVault operators. BrutalTrade posted the connection publicly, and additional links surfaced through an address called helloalan.eth, which had sent $1,800 and $2,500 to Kupia and separately sent $120 to the same scammer-linked Binance address. A further wallet associated with Kupia (linked to the GitHub account auditsea9) also appeared in the transaction trail.

Kupia responded that the $25 transaction dated to March 22, 2024 — 553 days before the rug — and represented an attempted purchase of an ENS domain or VPS service from a vendor that never delivered. As BrutalTrade later clarified, the intent of the tracing exercise was "to connect the dots... not to say that you are implicated," but rather to document that a relationship of some kind had existed. Kupia subsequently threatened legal action if the accusations continued, and BrutalTrade stepped back from direct implication while keeping the wallet-connection data on record. The episode illustrates a recurring limitation of on-chain forensics: shared wallet connections can be documented far more easily than actual intent.

07Aftermath

HyperVault spent weeks constructing an appearance of legitimacy — invented audit claims, video calls with prospective depositors, an integration with Hybra Finance, and an active social media presence. Behind that front sat an internal accounting system and an administrative override that made a large-scale exit possible at any time the operators chose. The withdrawal on September 25-26 executed that exit, moving $4.64 million out of nine vaults and through Tornado Cash before anyone could intervene. Nick Olsen and the associated development network have not resurfaced, leaving roughly 1,100 depositors with losses and little realistic path to recovery.

Reporting draws on on-chain analysis and commentary from HypingBull, PeckShield, CoinCentral, Cryptopolitan, olamidde, BeInCrypto, BrutalTrade, Rhadamant Memes, HYPEconomist, Zenith, Hybra Finance, and SpecterAnalyst.

HypervaultLiquidity ExtractionRug
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.