Purrlend on Hyperliquid facing extortion demand over alleged insider theft; attacker claims 48-hour deadline to return stolen funds or face law enforcement disclosure.
Security & Exploits ·
An onchain message sent to Purrlend on the Hyperliquid network contains an extortion demand, claiming the sender has identified an insider responsible for a theft and threatening to disclose KYC-linked exchange information and IP data to law enforcement unless stolen funds are returned within 48 hours. The message, posted to a wallet address on Hyperliquid's blockchain explorer, rejects Purrlend's stated explanation of a compromised signer and asserts the sender has traced fund flows to pinpoint an internal actor.
The demand represents an escalation beyond typical security disclosures or whitehat bounty frameworks. The sender frames the ultimatum as a final opportunity to avoid criminal exposure and public reputational damage, positioning the threat as both immediate and permanent in consequence. No timeline has been provided for what occurs after the stated 48-hour window, nor is it clear whether the sender possesses the materials claimed or is acting on investigation or speculation.
It remains unknown whether Purrlend has responded, whether any funds have been returned, or how the protocol or affected users plan to address the claim. The nature and scale of the original theft, the validity of the insider allegation, and whether law enforcement has been or will be involved have not been established.