All Insights
Live On-Chain Tracker

XRPL NFT Scam Tracker

The XRP-API.com NFT phishing-drain campaign tricks Xaman and other wallet users into signing "Safe XRPL verify message" transactions that drain their funds. This page tracks every confirmed drain on-chain and auto-updates as new scams are detected.

Campaign first observed 2022-11-09 · latest drain 2026-08-04 · data refreshed 0s ago

Ecosystem warning

David "JoelKatz" Schwartz, CTO of Ripple, has publicly warned XRPL users about this campaign. View on X →

Victim testimony

@xZBLUEx, FuzzyBear community member, was drained after accepting a bait NFT offer that swept his FUZZY holdings. View on X →

Total drained (XRP-equiv)
2.43M
1.88M XRP + 554.0K in tokens
Held by scammers
20.0K
99% already laundered
Wallets affected
721
unique victims drained
Drain events
1.2K
259 distinct tokens
NFTs flagged
44.3K
914 scam offers flagged
Scam wallets tracked
1.3K
auto-flagged on each new mint
Deep dive: we traced one operator behind this campaign — a single actor rotating a fresh "Verification Sign" minting wallet every 1–2 days across 528 wallets, with full addresses, transaction hashes, and the 200+ exchange destination tags he cashes out to. Read the investigation →

How the scam works

How victims are lured in

The hook. The attacker first social-engineers the victim with a fake airdrop, reward, staking, or token-claim opportunity, usually framed with urgency ("limited slots", "ends in 1 hour", "verify in the next 10 minutes"). The lure links to a phishing page that prompts you to connect your wallet. Connecting alone does not drain anything: the wallet just shares its address so the attacker can scan your balances. The drain only happens once you sign a transaction the attacker pushes to your wallet.

The same operator group runs multiple acquisition funnels in parallel:

  • X / Twitter spam. Dozens of fake accounts posing as Xaman support, Xaman developers, or admins of trending projects. Profiles are padded with purchased followers and bot engagement (likes, replies, retweets) to look legitimate at a glance. They reply to real users in trending XRPL threads with "verification" instructions linking to the bait.
  • Targeted impersonation. The dominant lure is Xaman("your wallet needs verification"), including fake events such as"Xaman Community Day" (no such event exists). Variants impersonate community-favorite projects like PHNIX, FuzzyBear, and other meme or DeFi tokens currently in the spotlight. The same drain mechanic adapts to whichever brand the victim trusts.
  • Telegram & Discord DMs. After a user posts a support question or joins a project channel, attackers DM them within minutes claiming to be a "support agent" or "moderator". Attackers will also pose as fellow community members, striking up casual conversation to build rapport before pivoting to social engineering. They funnel the conversation off the official server and into a one-on-one DM where they push the verification link or terminal-paste command.
  • "Exclusive group" bait. Inside a project's own Telegram or Discord, the target is invited to a privileged sub-group — a "whale group", an "OG holders" room, or a private alpha channel. Entry is gated behind a "membership verification": only after they agree to join are they asked to verify with their wallet — the same sign-to-drain trap. The exclusivity lowers the victim's guard because the invitation comes from inside a community they already trust.
  • Google search hijacking. The campaign runs typo-squatted domains and pays for Google Ads slots that appear above the real result when users search for XRPL wallets, marketplaces, or token names. A single character difference in the URL bar (or just clicking the top "Sponsored" result) lands them on a clone site that runs the same scripts.

Common thread: the attacker's only goal is to get the victim onto a page they control, or to get them to sign a transaction or paste a terminal command without reading it. The on-chain drain or the malware payload then follows automatically.

Attack flow at a glance

End-to-end path from first contact to drained wallet:

1Lure

Fake airdrop or reward on X, Discord, Telegram, or a Google-Ads phishing site.

2Connect wallet

Victim connects Xaman / Crossmark / GemWallet. Address shared, no funds moved yet.

3Spam offers

Attacker pushes NFTokenCreateOffer prompts non-stop, disguised as 'verification'.

4Outcome
Sign → drained.
Revoke → safe.

How the scam works (on-chain drain)

The attacker pre-targets the victim. After scanning their wallet, the attacker mints one NFT per asset the victim holds: XRP, LP tokens, IOUs, everything. Each NFT's URI encodes that specific balance, e.g. https://xrpl-api.com/api/nft/metadata?amount=11432359&asset=CSC%3ArCSCManTZ8ME…. The phishing endpoint dynamically returns matching metadata so each NFT renders in the victim's wallet as a stand-in for that exact balance, often dressed up to impersonate Xaman, XRPL.org, or a known marketplace.

The attacker then creates NFTokenCreateOffers with memos like "Verification: Safe XRPL verify message" plus "Info: idx:0;len:11". The wallet UI shows what looks like a routine verification, but each signature actually authorizes a sale of the targeted balance. Signing N "verifications" hands the attacker N specific assets: XRP first, then every held token.

When the victim signs, they are handing their XRP and tokens directly to the attacker. On-chain, the scammer has simply sold them an NFT. The attacker accepts the offer, the transfer settles as a normal on-chain payment indistinguishable from a legitimate trade, and the victim is left holding a worthless bait NFT. There is no path to reverse it.

How the attack got here. The earliest version of this campaign was crude: the attacker simply spammed NFTokenCreateOffer transactions at every wallet on the ledger, hoping a few victims would tap "accept" on whatever showed up in their inbox. Once wallets started flagging unsolicited offers as spam and hiding them by default, the operator shifted up the stack. The current variant abuses the wallet sign-in / push-notification flow: instead of pushing offers directly, the attacker lures the victim to a web app they control, where the page triggers a "verification" sign request that the wallet renders as a routine notification. The malicious payload is now wrapped in a UX the victim already trusts.

Evolving evasion. As detection has tightened across XRPL platforms and wallets, the campaign has shifted. The most recent variants mint blankNFTs with minimal or no on-chain metadata (no URI, no memo, sometimes no name), so URI and memo classifiers have nothing to match. We catch these by issuer-level reputation: any wallet that has ever produced a confirmed scam is auto-flagged on every subsequent mint and offer, URI or not. The list refreshes live and is published as scamIssuersList in the /api/nft/scam response so wallets can mirror it client-side.

Off-chain variant: terminal stealer payload

The same operators run a parallel attack that never touches the ledger. The bait NFT or a linked page prompts the user to "complete verification" by copying a string and pasting it into their desktop terminal (PowerShell on Windows, Terminal on macOS). The pasted line fetches a payload from a short-lived host (e.g. mmzzxcca.xyz/update3.zip) which deploys HijackLoaderplus SnappyClient, a commodity-stealer combo that exfiltrates browser cookies, saved passwords, and cryptocurrency wallet files, and installs persistence via a Run key plus DLL injection into SysWOW64\input.dll. See the public sandbox detonation at tria.ge/260505-k76d4afx2j (severity 10/10).

There is no XRPL signature involved: the loss happens entirely on the victim's machine, and the attacker can sweep funds from any wallet whose seed or session cookie was stored locally. Never paste anything from an NFT, Discord, Twitter, or website prompt into a terminal. No legitimate XRPL service ever asks you to do this.

Phishing page prompting the user to paste a verification code into their desktop terminal
Screenshot of the phishing page: a fake "verification" workflow that instructs the user to open their OS terminal and paste a copied string.
Recording of the lure in the wild. The victim is walked through opening their OS terminal and pasting an "update" command that silently installs the stealer.

Live on-chain data

Monthly drain timeline

MonthXRP drainedEvents
2026-08193.4K56
2026-07173.5K84
2026-06176.3K130
2026-051.06M499
2026-04228.7K135
2026-0398.0K47
2026-02446.2K164
2026-0137.7K50
2025-125831
2025-10701
2025-092462
2025-088881
2025-051501
2024-1201
2024-1115.5K11
2023-095891
2023-012012
2022-122501
2022-1113

Top scammer wallets (XRP received)

AddressXRP receivedDrains
r3qAzD…x6ia576.5K10
rKWQGG…MaTp353.3K102
rG8Vfi…1UTq190.9K104
rNszN3…eVq8163.5K1
rMKAzY…smaV157.3K39
rJdgNk…sZ3A95.8K9
rNRvAX…ev4k72.7K25
rTgWnj…RgCk63.2K1
rn98Kz…WRWu61.0K72
rwHTGu…LKB450.9K1

Top victim wallets (XRP paid)

Scammer wallet holdings (live)

Current on-chain holdings of every scam wallet, XRP plus IOU/LP tokens at market value. Compare against the 2.43M XRP-equiv drained from victims: 99% has already been moved off-chain (cashed out, bridged, or pushed through a tumbler).

WalletTotal (XRP-eq)Composition
r9JnKG…w7y8
23.67M ACM47.63M LP XRP/ACM
5.3K
9/5.2K
XRP / Tokens
rKWQGG…MaTp
6.17M REITF120.07M LP XRP/PONGO109.5K DARKNET497.1K RIBBLE
1.5K
41/1.4K
XRP / Tokens
rndes4…989c910
910/0
XRP / Tokens
rn98Kz…WRWu
16 XIO106.96B GANJA26.6K $XRPLedgerETF40 RLUSD
901
14/886
XRP / Tokens
rpmrDZ…eChZ
84.62M LP XRP/Phoenix68.76M Phoenix2.9K LP XRP/MAG550.1K SPT
852
157/695
XRP / Tokens
rMWj9F…RHAJ
1.63B DeepTide
609
3/605
XRP / Tokens
rPUtim…CdZ9
77.2K HEROES63.6K ACM30.7K XRG5.1K FLC
534
477/57
XRP / Tokens
rEXeXY…hiZo
1 RLUSD
492
490/1
XRP / Tokens
rhT1f6…7CgZ
89.8K XPM2.39M HCT
422
9/413
XRP / Tokens
rfotNC…uPKU
67.44M $BWTZ746 6662.7K GRIM2.7K RPR
411
5/406
XRP / Tokens
r4JECs…bWAV
2.19M ROOFxrp14.97T PEPE573 EVR1.13M CSC
374
15/359
XRP / Tokens
rMMdkU…cxPL
5.0K BEAR1 PHNIX
344
332/12
XRP / Tokens
rfSMGP…M98F
671.5K PHNIX0 BEAR0 RLUSD
338
331/6
XRP / Tokens
r3kkKv…d5sP
0 MAG1.74M FUZZY33.3K REAL5.3K XRT
238
6/232
XRP / Tokens
rMKAzY…smaV
3.82M FUZZY459.38B XRSHIB2.9K voltt263 CTF
233
9/224
XRP / Tokens
rN8yzA…1p96165
165/0
XRP / Tokens
rJAZKF…vdvo
5.4K XRAIN6 XDUDE9 POLAR200 2CD
164
163/1
XRP / Tokens
r4GwDN…itsV
0 MAG133 RPR0 BEAR0 DROP
149
135/14
XRP / Tokens
rJFiRE…bVj9
10.3K SOLO
128
2/126
XRP / Tokens
rNFTim…uv7s127
127/0
XRP / Tokens

Snapshot from the last cron run (10s ago). Top 20 wallets shown. XRP cash Tokens LP chip

Potential dump pressure: tokens held by scammers

Aggregate token positions across all 1.3K tracked scam wallets. If any of these tokens see a large market sell, the scammers are likely behind it. Sorted by current XRP-equivalent.

TokenIssuerAmount heldValue (XRP)Wallets
ACMrD2XHi…EUg223.82M3.9K4
REITFrLSCBS…LygX6.17M1.4K1
LP XRP/ACMLPr3E9wr…HLgp47.63M1.4K1
DeepTidernHDzE…hbFi1.63B6051
FUZZYrhCAT4…pR629.38M43494
XPMrXPMxB…wkoa93.3K42920
XIOrfuzio…RoxU174062
LP XRP/PhoenixLPrpREX8…vWwA84.62M2791
SOLOrsoLo2…rLZz20.3K24814
RLUSDrMxCKb…m5De222207129

Top 10 of 40 distinct tokens, by current XRP-equivalent.

Tokens drained (top 40 by frequency)

Value in XRP uses current market price for regular tokens, or AMM pool reserves for LP tokens. - means no price feed (illiquid or delisted).

RLUSDrMxCKb…m5De2.3K2.2K41
FUZZYrhCAT4…pR62684.84M31.7K36
PHNIXrDFXbW…ivmN2.09B19.9K25
SOLOrsoLo2…rLZz73.0K89221
CSCrCSCMa…gkwr436.17M14.9K17
REALrKVyXn…Nz88266.2K49015
BXErM1J2M…y87r166.6K39115
03C3BE9D…LP XRP/MAGrNZ2ZV…bXce278.0K10.5K13
XPMrXPMxB…wkoa115.0K52911
ARMYrGG3wQ…CBfC105.1K54410

Recent drains (live feed)

Every drain rebuilt as a three-step timeline: Minted — the attacker creates the bait NFT · Flagged — our detection marks it a scam · Drained — the victim signs the offer in their wallet. The gap between Flagged and Drained is our protection window: green when we flagged it in time, red when the signature beat us. Hover any address or hash for the full value.

WhenPaidMint → Flag → DrainVictim → ScammerOn-chain
1h ago
Aug 4, 10:16:10 UTC
14 XRP
Minted10:12:50+0sFlagged10:12:50+3m 20sDrained10:16:10
Flagged 3m 20s before drain
rnF4Ys…rXA3NFT 000801… ↗tx 48622B… ↗
5h ago
Aug 4, 06:16:01 UTC
161 XRP
Minted06:15:32+5sFlagged06:15:37+24sDrained06:16:01
Flagged 24s before drain
rnZfxf…FrkuNFT 000801… ↗tx 1C3B61… ↗
8h ago
Aug 4, 03:28:10 UTC
0 RLUSD
Minted15:26:02+5sFlagged15:26:06+12h 2mDrained03:28:10
Flagged 12h 2m before drain
rESajk…N6M5NFT 000800… ↗tx B26260… ↗
8h ago
Aug 4, 03:26:30 UTC
0 RLUSD
Minted03:02:51+2sFlagged03:02:53+23m 37sDrained03:26:30
Flagged 23m 37s before drain
rESajk…N6M5NFT 000800… ↗tx 326414… ↗
8h ago
Aug 4, 03:17:30 UTC
0 RLUSD
Flagged03:10:29+0sMinted03:10:30+7mDrained03:17:30
Flagged 7m before drain
rESajk…N6M5NFT 000800… ↗tx B0E8A8… ↗
9h ago
Aug 4, 02:44:40 UTC
2 XRP
Minted02:43:50+2sFlagged02:43:51+48sDrained02:44:40
Flagged 48s before drain
rfHntp…pVZVNFT 000801… ↗tx 05E328… ↗
9h ago
Aug 4, 02:22:12 UTC
3.0K XRP
Minted02:21:51+2sFlagged02:21:53+19sDrained02:22:12
Flagged 19s before drain
rNsAAV…kCwCNFT 000801… ↗tx 083039… ↗
12h ago
Aug 3, 23:46:52 UTC
14.4K XRP
Minted23:45:02+6sFlagged23:45:08+1m 44sDrained23:46:52
Flagged 1m 44s before drain
rLaRBJ…sfwsNFT 000800… ↗tx E00732… ↗
16h ago
Aug 3, 19:44:30 UTC
24 XRP
Flagged19:44:08+1sMinted19:44:10+20sDrained19:44:30
Flagged 21s before drain
rE5Ayo…8e3KNFT 000801… ↗tx 14EF19… ↗
21h ago
Aug 3, 14:38:40 UTC
415 RLUSD386 XRP
Minted14:36:51+3sFlagged14:36:53+1m 46sDrained14:38:40
Flagged 1m 46s before drain
rEyTA3…skvcNFT 000801… ↗tx 6AB712… ↗

Drains ≥ 10,000 XRP highlighted. Drains before the 16 Jun 2026 line predate xrp.cafe / Xaman consuming this feed and were not protected by it.

Protect yourself

How to protect yourself (users)

  • Never sign an NFTokenCreateOffer, or any transaction, you didn't deliberately start.
  • Treat memos like "Verification", "Safe XRPL verify", or "idx:N;len:N" as red flags. No legitimate XRPL service uses those.
  • If an NFT in your wallet shows a huge balance you never bought, do not click it (don't interact with things you do not understand). Check the URI: anything pointing to xrpl-api.com or xrp-api.com is the drain campaign.
  • Burn or hide suspect NFTs from your wallet instead of interacting with them.
  • Never paste a "verification" code into your terminal. If an NFT description, linked page, Discord/Twitter DM, or "support agent" tells you to open PowerShell/Terminal and paste a command, it is HijackLoader/SnappyClient or an equivalent commodity stealer. It will exfiltrate your browser cookies, saved passwords, wallet files, and stage persistence on your machine. No real XRPL service ever requires this.
  • If you've been drained on-chain, the transfer cannot be reversed. If your machine was compromised (terminal-paste variant), assume cookies + saved credentials + locally stored wallet seeds are all leaked: rotate exchange/email/social passwords from a clean device, revoke any active wallet sessions, and move XRPL funds to a fresh seed generated offline on hardware you trust.

Already got the spam offers? Revoke Xaman third-party app access

If you connected your Xaman wallet to one of the phishing sites and are now being spammed with NFT offers, cancelling each offer does not stop the attack. The attacker holds an active third-party app permission on your wallet and will keep pushing offers until you revoke it.

  1. Open Xaman → SettingsThird-party apps.
  2. Look for an app you don't recognise. Most commonly the malicious entry is labelled "XPMarket", but the attacker can rename it to anything (Xaman, FuzzyBear, RLUSD, an XRPL marketplace, etc.). The displayed name is not verified.
  3. Tap the suspicious app.
  4. Scroll to the bottom and tap Revoke access.

After revoking, the attacker can no longer create offers on your behalf. If you signed anything during the session, or if you can't remember exactly what you authorized, move remaining XRP, tokens, and any LP positions to a fresh seed generated offline.

For developers

For wallet & dapp developers: automatic scam detection

Free public endpoints cover the full integration surface. No API key required; data updates every minute.

1. Per-NFT scam check: GET /api/nft/<NFTokenID>

Already part of the standard NFT API. Returns the full NFT document; check the scam: true and scamType fields before rendering or accepting an offer.

curl https://api.xrpl.to/api/nft/00090000560ABF36DE406A9E7EE3B37CBBE047629EC1C40E956828E50634B54A
# → { "_id": "0009...", "scam": true, "scamType": "phishing_uri_domain", "issuer": "r3qAz...", ... }
2. Tracker snapshot + scam-issuer list: GET /api/nft/scam

Single endpoint with everything: aggregate stats, monthly timeline, top scammers/victims, recent drains, and a flat scamIssuersList (1.3K addresses today) for client-side filtering. Cache locally and filter incoming NFTs by issuer against the list; pre-empts any per-NFT round-trip for known-bad wallets. Refresh every few minutes.

curl https://api.xrpl.to/api/nft/scam
# → { "totals": { ... }, "monthlyTimeline": [ ... ], "topScammers": [ ... ],
#     "tokensDrained": [ ... ], "recentDrains": [ ... ],
#     "scamIssuersList": ["r3qAz...", "rGhwR5...", ...], ... }
3. Platform-wide scam blocklist + per-address check: GET /v1/scams/addresses · GET /v1/scams/check/<address>

Not NFT-only. /v1/scams/addresses returns the flat union of every flagged XRPL address — the NFT-phishing issuers above plus known payment drainers — and /v1/scams/check/<address>verifies a single counterparty. Cache scamAddressesList and reject any Payment or offer to a flagged address before signing.

curl https://api.xrpl.to/v1/scams/addresses
# → { "count": ..., "sources": { "scam_accounts": ..., "nft_scam_issuers": ... },
#     "scamAddressesList": ["r...", "r...", ...], "accounts": [ ... ] }

curl https://api.xrpl.to/v1/scams/check/rNVdQM2AupHsZfGfkHKR4qfPHcLYwwbmH3
# → { "is_scam": true, "category": "...", "reason": "...", "source": "verified" }

Suggested integration: on app load, fetch /api/nft/scam once and cache the scamIssuersList. For each NFT before rendering, check nft.issuer ∈ scamIssuersList first (O(1) client-side). If the issuer is clean but you want to verify the specific NFT, follow up with GET /api/nft/<NFTokenID>and check scam in the response. Detection is already live; flags appear on-chain within seconds of a new mint or offer.

The full XRPL.to API surface (tokens, AMM pools, NFTs, traders, OHLC, holders, search, and more) is documented at xrpl.to/docs. Free, no API key required for read endpoints, no rate-limit headaches for normal use. A modern alternative to the Ripple Data API with deeper filtering and richer query parameters.