Hyperliquid Faces Severe Attacks: Review, Reflection, and Future Challenges for DEX

robot
Abstract generation in progress

Reviewing Hyperliquid's Black Wednesday: Demand is the Starting Point, Correctness is the Endpoint

1. Feast of Crows

On March 26, the Dex project Hyperliquid was attacked again, marking the fourth major security incident since last November and the most serious crisis it has faced since its establishment. The method of this attack is quite similar to the previous incident of 50x leveraged long on ETH, but it was more precise and fierce, like a feast of crows targeting Dex.

The attacker chose the illiquid Meme token JELLY on Solana as a breakthrough point. At nine o'clock that evening, the attacker deposited 3.5 million USDC as margin into the platform, opening a short position of JELLY worth 4.08 million dollars, with the leverage reaching the platform's limit. At the same time, an address holding a large amount of JELLY began to sell on the spot market, causing the token price to plummet, resulting in a floating profit for the short position.

The attacker quickly withdrew 2.76 million USDC in collateral, leading to insufficient margin for the remaining short positions and triggering Hyperliquid's automatic liquidation mechanism. The platform's insurance vault, HLP, was forced to take over this massive JELLY short position. At this point, the attacker began to operate in reverse, buying a large amount of JELLY in a short period, causing its price to surge several times, resulting in a floating loss of over 10.5 million US dollars for HLP.

When Hyperliquid got into trouble, some centralized exchanges quickly intervened. They announced the launch of JELLY's perpetual contract within an hour after the attack event, which raised questions in the market.

In response to this crisis, the Hyperliquid Validator Committee voted to delist the JELLY perpetual contract, with the final closing price set at the attacker's opening price, resulting in a profit of $700,000 for HLP. Although this decision addressed the immediate crisis, it also raised questions about the level of decentralization.

Reviewing Hyperliquid Black Wednesday: Demand is the Starting Point, Correctness is the End Point

2. On-chain exchanges?

Hyperliquid, as a leading protocol in the on-chain perpetual contract sector, accounts for 9% of the global contract trading volume of a major exchange platform, placing it in a leading position among DEXs. In contrast, other DEX platforms collectively account for only about 5% of the contract trading volume of that exchange platform.

However, this Dex project, established after the collapse of a major trading platform, seems to be far less fortunate than other platforms and has even encountered more twists and turns. Since its launch, Hyperliquid has faced a major attack almost every month, putting it in a precarious situation. Here is a review of several major security incidents:

  1. December 2024: Potential Hacker Threats (Attempted Attacks)
  2. January 2025: ETH whale high leverage attack
  3. March 12, 2025: ETH Whale Second Attack
  4. March 26, 2025: JELLY Event

These events have exposed the risks of Hyperliquid in aspects such as margin mechanisms, HLP mechanisms, and centralization issues caused by the limited number of validators.

Fully decentralized Dex projects face numerous challenges, including the influence of physical teams, the centralization tendency of governance voting, issues of profit distribution, and the balance between capital efficiency and decentralization.

There are still some key issues for Perp Dex:

  1. Users care more about capital efficiency and project background rather than the degree of decentralization.
  2. How do algorithms and mechanisms respond to traders with information advantages in a high-leverage environment?
  3. Behind the narrative of no financing and high performance, there may be a more centralized decision-making model.
  4. In the absence of a dynamic risk control mechanism, how to differentiate between high-risk assets and mainstream assets?
  5. Will Hyperliquid repeat the mistakes of certain failed projects?

Review of Hyperliquid Black Wednesday: Demand is the starting point, correctness is the endpoint

3. Internal Issues of Hyperliquid

From a liquidity perspective, although Hyperliquid performs outstandingly in Dex, its whale deposits may normally account for nearly 20% of the platform's TVL. This means that if a larger-scale similar event occurs, it could trigger a mass exodus of whales, leading the platform into a liquidity crisis.

Architecturally, Hyperliquid is a Dex with its own Layer 1, consisting of HyperEVM and HyperCore. HyperCore acts as the matching engine of a centralized exchange and shares the same consensus layer (HyperBFT) with HyperEVM. Although this design is innovative, it also carries potential risks, such as inconsistent transaction states, synchronization delays, and cross-chain settlement delays.

The HLP (Hyperliquid Pool) vault is the cornerstone of the Hyperliquid ecosystem, utilizing a "on-chain order book + strategy pool" dual-track system. It provides users with returns and offers liquidity for perpetual contract trading on the platform. However, this design has also shown vulnerabilities when facing whale attacks.

4. The road is long and obstructed.

The development history of Perp Dex is long-standing, from the hybrid mechanism of dYdX to Hyperliquid's comprehensive simulation of centralized exchanges, achieving on-chain optimal levels in terms of yield and capital efficiency. However, how to address the challenges posed by decentralization while maintaining high efficiency remains an unresolved issue.

The road ahead for order book DEXs is still full of challenges, including liquidity fragmentation, security risks brought by on-chain transparency, and low governance efficiency. Nevertheless, Hyperliquid has made significant progress in the competition against centralized exchanges.

5. The market is always right.

The success of DeFi does not solely stem from its degree of decentralization, but rather from its ability to meet the needs of users that cannot be fulfilled in traditional finance through decentralization. Hyperliquid represents the successful paradigm of current Perp Dex, which can be seen as a Dex built on a single chain, as well as a centralized exchange that incorporates a transparent ledger.

As a product that maximally simulates a centralized exchange through blockchain technology, Hyperliquid inevitably carries some inherent efficiency issues of blockchain. In the short term, tightening leverage limits and improving various insurance mechanisms may help avoid the risk of system crashes.

In the long run, as an emerging product, Hyperliquid should not be limited by inherent thinking. In the exploration of governance and various mechanisms, it might be better to follow the principles established at its inception: prioritizing demand and efficiency.

Review of Hyperliquid Black Wednesday: Demand is the starting point, correctness is the endpoint

HYPE-0.31%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 6
  • Share
Comment
0/400
PermabullPetevip
· 10h ago
Dex is always fragile.
View OriginalReply0
BlockchainBouncervip
· 10h ago
The losses are unbearable to look at.
View OriginalReply0
FastLeavervip
· 10h ago
It's another day of disaster.
View OriginalReply0
GateUser-e87b21eevip
· 10h ago
Another DEX has fallen.
View OriginalReply0
SilentObservervip
· 10h ago
Wish you good luck.
View OriginalReply0
GateUser-9ad11037vip
· 11h ago
Vulnerabilities are ruthless, but people have feelings.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)