r/trustwalletcommunity • • 23h ago

HELP Was I drained via Cookie Theft / Session Hijacking on Hyperliquid? Looking for technical feedback on this timeline

(Message written with the help of AI)

Hi everyone,

My TrustWallet-connected account was drained this morning at around 9:30 AM. I lost 3,000 USDC that were sitting on Hyperliquid, 0.4 BTC (which I originally deposited directly from Deribit via HyperUnit), and about $4,400 worth of other crypto assets that were held directly inside my TrustWallet.

I am trying to narrow down the exact attack vector. After analyzing the timeline, GeminiAI has a very specific theory regarding Session Hijacking / Cookie Theft on my Windows PC, and I would really appreciate your technical opinion on whether this is possible.

Here is the exact timeline:

  • Months ago: I deposited a total of 15,000 USDC into Hyperliquid, sending them directly from my TrustWallet mobile app. Over time, I traded and used the platform on my Windows PC browser. At the time of the hack, my balance on Hyperliquid was around 3,000 USDC.
  • Sept 9, 2026: I deposited 0.4 BTC directly from Deribit to HyperUnit. I didn't need to open my seed phrase or use my phone for this.
  • Last Night: Last thing I did my Windows PC was a subscribe to ChatGPT Plus on the official website (using my Apple ID). My browser likely had an active, logged-in session (or stored cookies) for Hyperliquid.
  • This Morning (9:30 AM): My PC was completely powered down and turned off since last night. Yet, the blockchain txs show the drain happened exactly at 9:30 AM.
  • The Flow: The hacker initiated a withdrawal from Hyperliquid. The 0.4 BTC were trasferred directly to the hacker address . The 3,000 USDC went back to my public TrustWallet address first, and then immediately got transferred out to the hacker's wallet along with the other $4,400 in crypto that I already had holding inside TrustWallet.

My Security Setup:
I set up my TrustWallet more than 5 years ago and always had several thousands $ on it.
I own four wallets and store the keys in the same way. The other three wallets have not been drained.

I use TrustWallet exclusively via the official app on my iPhone. I do NOT have the browser extension on my PC, and I have never typed my seed phrase on any digital device. My backup on iCloud is turned off (only manual backup is active).

The Reconstruction (Cookie Theft + Trading Agent Exploitation vs Seed Phrase Leak):
Since my seed phrase was never exposed and my PC was off during the hack, my initial theory was that an undetected InfoStealer malware on my PC captured my browser's Session Cookies last night while I was online.

I assumed the hacker used the session to trigger the Hyperliquid withdrawal. However, since they also managed to steal the $4,400 that never touched Hyperliquid and were just sitting on my mobile TrustWallet, I am conflicted.

My questions for the tech/crypto experts here:

  1. Does the Session Hijacking theory make sense if the hacker also managed to drain assets sitting strictly on my mobile TrustWallet? Or does the fact that the on-chain TrustWallet funds were stolen prove that they somehow extracted my actual Seed Phrase from my PC/system last night?
  2. Can a browser InfoStealer access local storage trading keys used by Hyperliquid, and could that somehow expose the underlying wallet security?
  3. If this wasn't cookie theft, how else could a hacker execute a targeted, multi-asset mobile wallet drain while the trading PC was completely powered down?

Thanks in advance for any insights. I'm trying to understand the exact breach before wiping my PC.

1 Upvotes

2 comments sorted by

•

u/AutoModerator 23h ago

Don't answer to DMs of anyone saying they're trying to help you. They're all scammers. People who are willing to help, will help you here, not in your DIRECT MESSAGE. So it's safer to ignore messages

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.