Hyperdrive, a DeFi protocol within the Hyperliquid ecosystem, has suffered a significant security breach due to a contract vulnerability. The attack occurred when users set the Router as the Operator, allowing it to execute calls on any contract in the whitelist, including the Market contract. This flaw enabled a third-party address to manipulate user positions, potentially resulting in a loss of $700,000. The attack involved specific contract addresses, namely Router (0x8D9e…) and Market (0xa522…). As of now, the Hyperdrive project team has not issued a response regarding the incident. The vulnerability highlights ongoing security challenges within the DeFi space.