Worked example · 2025-11
Hyperliquid POPCAT spoofed-buy-wall + cancel-flood manipulation — Hyperliquid (HyperEVM L1) — 2025-11-12 to 2025-11-13
Summary
Hyperliquid is a perpetual-futures DEX operating on its own L1 (HyperEVM, post-2024). Liquidations on Hyperliquid that exceed order-book depth are inherited by the HLP (Hyperliquid Liquidity Provider) market-making vault, which serves as counterparty-of-last-resort. The HLP held approximately $230M+ in assets at the time of the POPCAT incident. POPCAT is a Solana-launched memecoin (full ticker POPCAT (SOL)) listed as a perpetual on Hyperliquid; the perp's order-book depth was thin relative to the manipulation volume the attacker brought to the venue.
On 2025-11-12, an attacker withdrew approximately $3M USDC from OKX (with secondary funding from Bybit) and bridged the USDC to Hyperliquid via Arbitrum across approximately 19-26 coordinated wallets. The wallets opened long positions totaling ~$20-30M in POPCAT perpetuals at up to 10x leverage, building a substantial long-side exposure. Around 16:00 UTC, the attacker placed a fake buy wall of approximately $25M aggregate across the 19-26 wallets at the ~$0.21 price level, manufacturing an apparent demand signal. The buy wall pushed POPCAT's mark price up approximately 30%. Other market participants — both market-takers responding to the apparent depth and other long-position-holders extending exposure — adjusted their positions on the assumption that the buy wall represented real liquidity.
The attacker then abruptly cancelled the entire buy wall. With the manufactured demand removed, the order book's true thinness was exposed; POPCAT's mark price crashed approximately 43% to $0.12 within minutes. The price crash triggered a cascading liquidation event affecting both the attacker's own long positions (deliberately sacrificed) and other long-position holders on the venue. Total liquidations during the cascade were approximately $63M; the attacker's deliberate sacrifice on Hyperliquid was approximately $3M. The HLP vault inherited the residual bad debt of approximately $4.5M-$4.9M because the cascade exceeded the order-book depth's ability to clear positions at the trigger prices.
Per Specter's on-chain analysis published 2025-11-14 (cited across CoinDesk, Cryptopolitan, Tekedia, CryptoRank, ChainCatcher), the realised-profit channel for the attacker was opposite-side short exposure held on OKX / Bybit. The Hyperliquid leg's net loss (~$3M sacrificed) was the cost-of-manipulation; the off-Hyperliquid short profited from the manipulated price-discovery distortion at a magnitude that exceeded the on-Hyperliquid sacrifice. The cross-venue manipulation primitive — spoof orders posted on Hyperliquid to influence price-discovery that the attacker captured on OKX / Bybit — is the boundary case between T17.003 (load-bearing on Hyperliquid's order book) and T17.001 (cross-venue propagation that produces the off-venue profit channel).
Hyperliquid temporarily paused some withdrawals during the post-event scrutiny window (per Decrypt / Yahoo Finance reporting); no validator-set settlement was applied to POPCAT positions (unlike the March 2025 JELLY case where positions were forcibly settled at $0.0095). The HLP vault absorbed the bad-debt outcome.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| pre-2025-11-12 | Hyperliquid POPCAT perp listed; order-book depth thin relative to attacker-class manipulation volumes; HLP vault inheritance design unchanged from March 2025 JELLY incident (no per-token concentration cap, no per-position size cap, no listing-guards on cross-venue depth ratio) | (standing T17.002 + T17.003 surface) |
| pre-2025-11-12 | Attacker pre-positions: opens off-Hyperliquid short exposure on POPCAT on OKX / Bybit (per Specter's reconstruction); funds 19-26 Hyperliquid wallets with ~$3M USDC sourced from OKX / Bybit and bridged via Arbitrum | T8.001 (cluster setup) + T17.001 (cross-venue setup) |
| 2025-11-12 (multi-hour pre-event window) | Attacker opens ~$20-30M aggregate long positions in POPCAT perps across the 19-26 wallets at up to 10x leverage | T17.002 setup (cascade-ignition positioning) |
| 2025-11-12 ~16:00 UTC | Attacker places fake buy wall of ~$25M aggregate across the 19-26 wallets at ~$0.21 POPCAT price; POPCAT mark-price rises ~30% on the manufactured demand signal | T17.003 ignition (buy-wall posting) |
| 2025-11-12 T+minutes | Attacker abruptly cancels the entire buy wall; manufactured demand removed; POPCAT mark-price crashes ~43% to $0.12 within minutes | T17.003 + T17.002 (cancel-flood + cascade ignition) |
| 2025-11-12 T+minutes | Cascading liquidations propagate across long positions; total liquidations ~$63M; attacker's own long positions deliberately sacrificed for ~$3M loss; HLP vault inherits ~$4.5-4.9M residual bad debt | T17.002 (cascade extraction) |
| 2025-11-12 T+hours | Attacker's off-Hyperliquid POPCAT shorts on OKX / Bybit settle profitably against the manipulated mark; cross-venue profit channel realised | T17.001 (cross-venue extraction) |
| 2025-11-13 | Hyperliquid temporarily pauses some withdrawals as the POPCAT-trader cluster draws scrutiny; community-side trace data published | (operator response — partial) |
| 2025-11-14 | On-chain analyst Specter publishes investigation alleging BTX Capital + Vanessa Cao orchestration; cites TST-wallet reuse, BTX Polygon-multisig funder-graph links, and AKI-token deposit pattern | (forensic record — inferred-strong attribution) |
| 2025-11-14 to 2025-11-20 | Cao publicly denies involvement, demands apology; CoinDesk / Cryptopolitan / Tekedia / CryptoRank / ChainCatcher / The Block independently corroborate the on-chain trace material at the funder-graph-cluster layer; named attribution remains contested | (cohort context) |
| ongoing | No regulatory enforcement action published at v0.4 reference cutoff; Hyperliquid governance changes scheduled in response to the third 2025 manipulation incident | (governance response) |
What defenders observed
- Pre-event (HLP-vault inheritance design — third recurrence): Hyperliquid's HLP vault inheritance design absorbed the cascade bad-debt for the third time in 2025 (after JELLY March and an additional July incident, per CCN's "third manipulation attack" framing). The structural surface — centralised-liquidity vault as counterparty-of-last-resort with no per-token concentration cap, no per-position size cap, and no listing-guards on cross-venue depth ratio — is identical to the JELLY March 2025 case (
examples/2025-03-hyperliquid-jelly-self-liquidation-cross-venue.md). The cross-incident lesson-propagation gap inside Hyperliquid's own design space (8 months between JELLY and POPCAT, with no listing-guards added) is structurally identical to the cross-protocol propagation gap observed in Vee Finance September 2021 (examples/2021-09-vee-finance.md) and in Shibarium September 2025 (examples/2025-09-shibarium-bridge.md). Future T17.x contributions documenting venue-side cases should track intra-venue lesson-propagation gaps as a discrete observation class — designs that absorbed an extraction once and did not adjust before the next extraction. - Pre-event (cross-venue setup): the attacker pre-positioned off-Hyperliquid short exposure on OKX / Bybit before opening the on-Hyperliquid long positions. The cross-venue setup is the load-bearing T17.001 surface — closing T17.003 at the Hyperliquid order-book layer would not close T17.001 at the cross-venue profit-channel layer; the attacker would still profit from the off-venue shorts. The mitigation surface is therefore at cross-venue cohort attribution (CEX deposit-side trace data integrated with on-DEX wallet attribution) — venue-side compliance has the trace data but operator-cooperation between Hyperliquid and centralised exchanges is structurally limited at v0.4. Per Specter's analysis, the CEX deposit-side trace was the load-bearing forensic signal for the attribution layer.
- At-event (buy-wall posting signature): the buy-wall posting across 19-26 wallets at the ~$0.21 level was visible in the per-order event stream at the Hyperliquid sequencer layer. A real-time spoof-detection monitor that correlated concurrent large-bid postings across funder-graph-clustered wallets with one-sided economic exposure (the cohort's executed long positions on the same venue) would have produced a high-confidence T17.003 signature in the same minute. Hyperliquid's runtime risk-engine layer did not deploy this detector at the time of the POPCAT incident; the trace was reconstructed post-event from public order-book data.
- At-event (cancellation event signature): the synchronised cancellation of the buy wall across 19-26 wallets within seconds is operationally indistinguishable from honest-market-maker quote updates at the per-order layer, but distinguishable from honest market-making at the cohort-coordination layer: honest market-makers do not synchronise cancellation across 19-26 separately-owned accounts. The detection signal is funder-graph-cluster-wide synchronised cancellation — a post-hoc cohort-attribution signal rather than a real-time per-order signal. Specter's reconstruction operated at this layer.
- At-event (cascade propagation): the cancellation triggered a cascading liquidation event across long-position holders. The HLP vault inherited ~$4.5-4.9M residual bad debt because the cascade exceeded order-book depth's ability to clear positions at the trigger prices. The structural mitigation is per-token concentration caps + per-position size caps + per-cascade-block liquidation throttling at the HLP-vault layer (OAK-M11-class) — Hyperliquid did not deploy these at the time.
- Post-event (no validator-set settlement): unlike the March 2025 JELLY case where Hyperliquid validators voted to settle positions at $0.0095, no validator-set settlement was applied to POPCAT positions. The HLP vault absorbed the bad-debt outcome. The asymmetric operator response (validator settlement for JELLY, no validator settlement for POPCAT) reflects the operator-side judgment that the validator-set discretionary-settlement primitive is best preserved for narrow-class incidents (here: the JELLY self-liquidation primitive was uniquely defeasible by an off-mark settlement; the POPCAT spoof-and-cancel primitive could not be defeated by an off-mark settlement because the manipulation had already propagated to off-venue shorts before the cancellation). The cross-incident asymmetry is itself a structural observation: the validator-settlement recovery channel does not generalise across all T17.x sub-shapes.
What this example tells contributors writing future Technique pages
- T17.003 has now landed at extraction-scale in the OAK corpus. POPCAT November 2025 is the cleanest T17.003 anchor at v0.4 with quantified dollar-loss attribution. The class qualifies for promotion from
drafttoemergingin a future minor version. The structural distinction from T3.002 (wash-trade volume inflation) is preserved — POPCAT did not fake executed volume; it faked resting-order state via the buy wall, then cancelled before fill. The structural distinction from T5.004 (sandwich MEV) is preserved — POPCAT did not manipulate executed transaction order; it manipulated the resting order book. - Crypto-DEX spoofing realised-profit lives off-venue. The realised-profit channel for crypto-DEX spoofing typically lives at the cross-venue layer — the attacker accepts a sacrifice-loss on the manipulated venue (~$3M here) to drive price-discovery distortion that profits opposite-side exposure on centralised venues (where the on-DEX manipulation is not the venue at risk). Future T17.003 cases should explicitly check for off-venue opposite-side exposure as the load-bearing profit channel, and dual-map T17.001 when present.
- Coordinated multi-wallet spoofing requires cohort attribution, not per-order analysis. The buy-wall placement across 19-26 wallets is operationally indistinguishable from a single large-trader's order placement at the per-order layer. Only funder-graph clustering across the wallets — or CEX deposit-side trace data integrating wallet attribution — exposes the cohort. T17.003 detection at v0.4 lives at the cohort-attribution analytical tier, not at the runtime risk-engine layer.
- Intra-venue lesson-propagation gaps are a tracked observation class. Hyperliquid's HLP vault inheritance design absorbed the JELLY March 2025 cascade, then a July 2025 cascade, then the POPCAT November 2025 cascade — three sequential extractions on the same structural surface in a single calendar year. Future T17.x and T9.004 contributions should track intra-venue lesson-propagation gaps alongside cross-protocol lesson-propagation gaps (Vee Finance vs. bZx) and cross-sub-domain lesson-propagation gaps (Shibarium vs. Beanstalk) — the three propagation-gap shapes are distinct and each carries different defender-side action implications.
Public references
- CoinDesk — Alleged POPCAT Manipulation Hits Hyperliquid with $4.9M Loss: Blockchain Analyst — contemporaneous press; canonical for the ~$4.9M HLP bad-debt figure and the spoofed-buy-wall + cancel framing —
[coindeskpopcat2025]. - CCN — Hyperliquid Hit by Third Market Manipulation Attack in 2025 — $5M in Bad Debt After POPCAT Crash — contemporaneous press; canonical for the "third 2025 manipulation incident" framing, the $3M-attacker-sacrifice / $4.9M-HLP-loss accounting, and the $25M buy wall mechanic —
[ccnpopcat2025]. - Halborn — Explained: The Hyperliquid Hack (November 2025) — independent audit-firm forensic walkthrough; cited for the technical mechanism of the spoof-and-cancel primitive —
[halbornhyperliquidpopcat2025]. - Cryptopolitan — BTX Capital's Vanessa Cao denies role in POPCAT manipulation on Hyperliquid — contemporaneous press; cited for Cao's public denial and the disputed-attribution framing —
[cryptopolitanpopcat2025]. - Tekedia — POPCAT Attack on Hyperliquid linked to BTX Capital Founder Vanessa Cao — contemporaneous press; cited for the BTX Capital + Vanessa Cao on-chain-attribution material from Specter's reconstruction —
[tekedipopcat2025]. - CryptoRank — Hyperliquid loses $4.9M in POPCAT price attack as new on-chain evidence points to BTX Capital — contemporaneous press aggregator; cited for cross-source corroboration of the BTX Capital attribution material —
[cryptorankpopcat2025]. - Decrypt — Hyperliquid Temporarily Paused Some Withdrawals as Popcat Trader Draws Scrutiny — contemporaneous press; cited for the operator-side withdrawal-pause response —
[decryptpopcat2025]. - ChainCatcher — Opinion: BTX Capital is accused of "maliciously manipulating" the prices of projects like POPCAT on Hyperliquid — contemporaneous press; cited for additional cross-source corroboration of the cohort-level attribution and cross-incident reuse (TST August 2025) —
[chaincatcherpopcat2025].
Citations
[coindeskpopcat2025]— contemporaneous press; canonical for the $4.9M HLP bad-debt figure and the spoofed-buy-wall framing.[ccnpopcat2025]— contemporaneous press; "third 2025 manipulation incident" framing and detailed mechanic.[halbornhyperliquidpopcat2025]— independent audit-firm forensic walkthrough.[cryptopolitanpopcat2025]— contemporaneous press; Cao's public denial.[tekedipopcat2025]— contemporaneous press; BTX Capital attribution material.[cryptorankpopcat2025]— press aggregator; cross-source corroboration.[decryptpopcat2025]— contemporaneous press; operator-side withdrawal-pause.[chaincatcherpopcat2025]— contemporaneous press; cross-source corroboration of cohort attribution.[zhou2023sok]— academic taxonomy classifying spoofing as a recurring market-manipulation class.[chainalysis2025rug]— market-manipulation aggregate.
Discussion
POPCAT November 2025 is the canonical 2025 worked example for T17.003 (one-sided spoof) composing with T17.002 (cascade engineering) and T17.001 (cross-venue profit-realisation) in the perp-DEX setting. It pairs with the CFTC vs Sarao 2015 anchor outside crypto (equity-futures CME context, the canonical T17.003 enforcement-record reference) as the crypto-DEX-specific sub-domain anchor. The cross-domain lesson-propagation observation is structurally significant: the Sarao precedent was published, well-known, and discussed at the regulator / market-microstructure layer; the same Technique class manifested at extraction-scale on Hyperliquid 10 years later despite the operational pattern being well-documented. Future T17.003 contributions should track this as a multi-decade cross-asset-class propagation gap — the lesson is not bounded by chain or venue, but by the design choice of whether the venue deploys per-order-lifecycle spoof-detection at the matching-engine layer.
The cross-venue profit-realisation framing is the load-bearing T17.001 contribution from this case. Unlike JELLY March 2025 where the cross-venue propagation went into the attack surface (Solana spot → Hyperliquid perp mark), POPCAT November 2025 has the cross-venue propagation going out of the attack surface (Hyperliquid mark → OKX / Bybit shorts). The two case shapes are dual instances of the T17.001 class: the cross-venue spread can be the input to the manipulation (JELLY) or the output of the manipulation (POPCAT). Future T17.001 contributions should distinguish these two sub-shapes explicitly.
The intra-venue lesson-propagation gap (JELLY March → July → POPCAT November) is the third structural lesson. Three sequential extractions on the same structural surface in a single calendar year, with no listing-guards or per-token concentration caps added between the extractions, demonstrates that the operator-side cost of adding listing-guards exceeded the per-incident absorbed loss in Hyperliquid's internal cost-benefit calculation. This is a discrete observation class distinct from the cross-protocol lesson-propagation gaps (where the lesson lived in a different protocol and did not transfer). Defender-side implication: when evaluating venue-side concentration risk, the intra-venue recurrence rate of similar-shape extractions is a load-bearing forward-looking signal — Hyperliquid's three-extractions-in-2025 record is itself the indicator.
Attribution-strength is inferred-strong (cohort-level, disputed). The on-chain forensic record at the funder-graph-cluster layer is published (Specter's reconstruction, cross-referenced by CoinDesk / Cryptopolitan / Tekedia / CryptoRank / ChainCatcher / The Block), but the named-attribution layer remains contested by Cao's public denial. OAK records the disputed status honestly: the cluster-level attribution to BTX Capital's on-chain footprint is well-corroborated; the named-individual attribution to Cao depends on the inference chain from the BTX Polygon-multisig to Cao's public Ethereum wallet. Future contributions citing this case for attribution-strength purposes should preserve the disputed-attribution nuance.
False-positive considerations: legitimate market-making activity routinely produces large posted limit orders that are subsequently cancelled as market conditions change; cancellation rates of 90%+ are typical for honest market-makers. The detection signal is not "high cancellation rate" but specifically "synchronised cancellation across funder-graph-clustered wallets combined with one-sided economic exposure on opposite-side off-venue positions" — three layers of cohort-attribution analysis that distinguish T17.003 from honest market-making. Per-order-layer analysis at the runtime risk-engine layer is structurally insufficient to identify T17.003 reliably; the cohort-attribution analytical tier is the load-bearing detection surface.
v0.x deferred items: track the v0.5 minor-version promotion of T17.003 from draft to emerging once this anchor is stable; cohort-level metrics on synchronised-cancellation distribution across major perp-DEX venues; integration of CEX deposit-side trace data with DEX wallet attribution as a load-bearing T17.003 detection primitive.