Home
/
Security measures
/
Wallet security
/

Session hijacking theory: crypto theft investigation

TrustWallet Account Drained | Concerns Over Session Hijacking on Hyperliquid

By

Elena Vasilyeva

Sep 25, 2026, 12:49 PM

Edited By

Clara Meier

3 minutes reading time

A person examines a computer screen filled with graphics and data related to crypto theft investigation
top

A user claims their TrustWallet-connected account was drained early today, losing significant crypto assets in a potential session hijacking incident. The attack, said to have occurred despite the user's PC being powered down, raises critical questions about security vulnerabilities in the ecosystem.

Incident Overview

The individual reported losing 3,000 USDC, 0.4 BTC, and another $4,400 worth of crypto following suspicious transactions on Hyperliquid. This situation highlights possible attack vectors as the user seeks technical opinions on their theory surrounding cookie theft.

"My PC was completely powered down yet the drain happened exactly at 9:30 AM," the user remarked.

The Technical Breakdown

Here's a summary of the timeline leading up to the incident:

  • Months ago: Deposited 15,000 USDC into Hyperliquid.

  • September 9, 2026: Transferred 0.4 BTC from Deribit to HyperUnit without opening the seed phrase.

  • Last Night: Completed a subscription to ChatGPT Plus, possibly leaving sessions active.

  • 9:30 AM: Transactions draining accounts initiated despite the PC being off.

The hacker managed to withdraw BTC to their wallet and transferred USDC back to the userโ€™s TrustWallet before draining it. The core of the userโ€™s theory is centered on a potential undetected InfoStealer malware capturing session cookies while active on the browser.

Community Reactions

Comments on forums about the incident reveal mixed insights:

  • "Seems like you approved the malicious contracts before, not seed phrase leaked," advised one user.

  • Another noted, "Send us your tx hashes so we could look into it."

Thereโ€™s a growing sentiment among community members that a previous approval of malicious contracts may have facilitated the attack, rather than a seed phrase leak.

Possible Vulnerabilities

Several crucial points arise from this situation:

  • Was Cookie Theft the primary attack vector?

  • Can a browser InfoStealer grab access to local storage trading keys used by Hyperliquid?

  • How did the hacker withdraw assets from a mobile wallet while the PC was powered down?

Key Insights from the Community

  • โ—‡ The majority believe that the user might have unknowingly interacted with malicious contracts.

  • โ–ฝ Concerns grow over broader security measures within decentralized exchanges.

  • โ€ป "If you don't control your keys, you don't control your funds," echoed a forum member.

Closure

As this developing story unfolds, the implications for TrustWallet and other wallets could lead to increased scrutiny of security protocols in decentralized finance. Users are urged to remain vigilant and consider all possible attack vectors. It's essential to understand the breach process before taking necessary steps to secure assets.

For further reading on securing your crypto assets, consider checking reputable sources in the crypto community.

Trends to Watch in Crypto Security

As investigations continue, there's a strong likelihood that TrustWallet and other platforms will enhance their security protocols in response to this attack. Experts estimate around an 80% chance that decentralized exchanges will implement stricter measures to prevent session hijacking, focusing on user education regarding contract approvals and the potential risks of active sessions. Increased awareness and stricter transaction monitoring are also probable, as these incidents highlight vulnerabilities that could put user assets at risk. The landscape of crypto security may shift significantly, with the community pushing for greater transparency from wallet providers and exchanges.

Lessons from the World of Sports

The current crypto crisis echoes an incident from the sports world: how a previously dominant football club fell from grace after ignoring systemic weaknesses. Years back, a top-tier team continuously faced unexpected injuries due to inadequate conditioning protocols. Just like the unaddressed flaws in their training led to a series of unfortunate defeats, todayโ€™s oversight in crypto security can lead to significant losses if not addressed. This parallel serves as a stark reminderโ€”if entities within crypto do not prioritize a resilient security framework, they may face a downfall similar to that of teams failing to adapt in a fast-evolving game.