
6 min read
MAS Investor Alert List: What Hyperliquid’s Entry Really Means
In late June 2026, the Monetary Authority of Singapore added Hyperliquid to its Investor Alert List. A fair number of headlines treated it as a ban.
It isn't one. MAS says entities on the list "may be wrongly perceived by the public as being licensed, authorized, or otherwise regulated" by MAS, and that inclusion "does not by itself indicate wrongdoing or constitute an enforcement action." Hyperliquid's own response said the same thing and added that it "has never claimed to be licensed or authorized by MAS."
Here is the detail that settles the argument faster than any of that. Binance is on the list. So are KuCoin, Bitget and Bybit, the last of these added earlier in the same month.
Whatever the Investor Alert List is, it is not a register of suspected bad actors. The largest exchange in the world is on it.
What the list is actually for
MAS has maintained it since 2004, and its purpose is narrower than almost everyone reporting on it assumes.
The list answers exactly one question: has MAS authorised this entity?
When the answer is no and the public might reasonably assume otherwise, the name goes
up. That is the whole test.
The trigger is not misconduct. It is the potential misperception of regulated status.
So an entry tells you nothing about solvency, security, governance or conduct. It tells you that a firm operating in view of Singaporean consumers does not hold a Singaporean authorisation — which, for an offshore exchange serving a global user base, is frequently just a description of its business model.
An alert list entry is a label, not a judgment. Reading it as an accusation gets the direction of the information exactly backwards.
Where Singapore has actually restricted things
This is worth separating out, because Singapore *has* imposed real constraints on crypto firms and none of them arrived via the alert list.
Marketing digital payment token services to the general public has been restricted since January 2022 — no public advertising, no promotion in public spaces. From 2024, digital payment token providers have been barred from offering credit, leverage or trading incentives to retail customers.
Those are rules with force, and they apply to licensed entities. The alert list applies to everyone else, and all it does is name them.
Notice the asymmetry. The firms subject to Singapore's hardest retail protections are the ones inside the perimeter. The firms on the alert list are outside it, and the only consumer protection available against an entity a regulator cannot license is to say so out loud.
What changed, and what didn't
For the network: nothing. Hyperliquid's statement is accurate — its infrastructure is unchanged, users retain self-custody, transactions settle on-chain. No access was restricted and no Singaporean was blocked.
For your compliance file: something did.
The name is now on a regulator's published page. Whatever the entry does or does not legally mean, that is a fact your banking partners can see, your auditors will find, and your board will eventually ask about. "MAS clarified it isn't enforcement" is a correct answer and a thin one, six months later, in a room where someone has printed the page.
This is the gap institutions consistently underestimate. Regulatory *status* is binary and usually easy to establish. Regulatory *signalling* is neither, and it moves the counterparties around you long before it moves any law. A venue can be fully compliant with every rule that applies to it and still become expensive for your bank to sit next to.
Three questions this should prompt
Do you know which of your venues are licensed, and by whom, for what?
Not "are they regulated" — which regulator, under which regime, covering which activity. A firm holding a payments licence in one jurisdiction and nothing in yours is a different risk from one holding neither, and both get described as "regulated" in a pitch deck.
Do you monitor alert lists as a standing control, or as an incident?
MAS, the FCA, ASIC, the SFC and BaFin all publish equivalents and update them without notice. If you learned about the Hyperliquid entry from a headline, that is your answer. And if you are going to monitor them, monitor them properly —an alarm that fires when Binance appears on a list Binance has been on for years is worse than no alarm.
If a venue you use becomes commercially awkward tomorrow, what does moving
look like?
This is the one that actually costs money. Assets you can move under your own authority are a different asset class from balances that require someone else's operations team to co-operate — a distinction that stays theoretical right up until it doesn't.
That last question is a custody question, and the answer hasn't changed. If you hold the keys, exiting a venue is a transaction. If you don't, it is a request. CoinsDo builds on the first model — the operator holds the keys at all times, CoinSend carries the approval policy and
withdrawal execution, and CoinGet runs automatic KYT screening on incoming addresses, so counterparty risk is assessed when funds arrive rather than reconstructed afterwards.
The thing to take away
An alert list entry is not an accusation, and reporting it as one produces exactly the confusion the list exists to prevent. It is a regulator declining, in public, to vouch for something — and vouching or declining to vouch are the only two positions available when an entity sits outside the perimeter.
MAS did not say Hyperliquid had done anything wrong. It said it has no relationship with them, which is true, which Hyperliquid agrees with, and which is also true of most of the exchanges your desk has used this year.

