Insights
Live · updated 0s ago

XRPL Payment Drain Tracker

A live, on-chain record of the “Safe XRPL verify message” payment drain on the XRP Ledger. In a scam similar to the Xaman/XPMarket NFT phishing, victims are tricked into signing a Payment — not handing over a seed — that sweeps their XRP and tokens to attacker-controlled wallets. We flag the destination wallets the instant a drain lands, so wallets and dapps can block them before the next victim signs.

Think you’re being drained right now?

Don’t panic. Nothing leaves your wallet unless you sign — simply connecting, or the request spam by itself, cannot move your funds. If you’re not sure what to do, close the app or tab and ask for help before signing anything.

  1. Do not sign any “verification” transaction. No legitimate wallet check requires you to sign a Payment.
  2. Move remaining funds to a fresh wallet you create offline; assume the connected wallet is compromised.
  3. Revoke the malicious app’s access in your wallet (per-wallet steps are under each demo below) and never re-import your seed into a site.
  4. Check a counterparty before signing: GET https://api.xrpl.to/v1/scams/check/<address>.
XRP swept
271.8K
+ tokens below
Drainer wallets
16
all blocklisted
Victims
49
Drain payments
55
First seen
2026-03-03
Latest drain
4h ago

Attack flow at a glance

1Lure

A fake "verification", airdrop, or poll on a Xaman / XPMarket lookalike.

2Connect

Wallet connects so the site can scan balances. No funds move yet.

3Sign "verify"

The prompt is really a Payment whose Destination is the attacker.

4Swept

One signature sends the victim's XRP and tokens to the attacker.

Connecting is harmless on its own — the loss happens only at step 3, the instant a Payment is signed.

How victims get baited

The drain only works once you’re on the attacker’s page. Like the similar XRPL NFT offer-spam scam, it runs several lures in parallel — almost always wrapped in urgency (“verify in 10 minutes”, “limited slots”):

Circulating now · fake
“Community Day Is Live. Monthly XRP Release. 10% Back to Holders.”

There is no “Community Day”, no “Monthly XRP Release”, and no “10% back to holders” program — none of this exists. It is just the current wrapper on the same sign-to-drain Payment.

  • X / Twitter replies. Fake “Xaman support” / project-admin accounts, padded with bot followers, reply in trending XRPL threads with “verification” links.
  • Brand impersonation. Mostly Xaman (“your wallet needs verification”, fake “Xaman Community Day”), plus spotlight tokens like PHNIX or FuzzyBear.
  • Telegram & Discord DMs. A “support agent” or “moderator” DMs you after you post in a channel, then funnels you to the bait link.
  • “Exclusive group” bait. An invite to a whale / OG-holders room gated behind a “membership verification” — the same sign-to-drain trap.
  • Google search hijacking. Typo-squatted domains and paid “Sponsored” ad slots sitting above the real result for wallet / marketplace searches.

These lures mirror a similar scam’s playbook — full breakdown there: XRPL NFT Scam Tracker → How victims are lured in.

How the verification-sign drain works

It is a server-driven signature drainer: the attacker’s backend authors the transaction and the victim signs it in their own wallet on a lookalike like poll-xaman.app. The seed is never typed or collected — so the “never share your seed” warnings never fire.

What the victim actually signs — the friendly “Safe XRPL verify message” prompt at step 3 above — is a Payment whose Destination is the attacker’s wallet. There is no “verification” transaction type on the XRP Ledger; the word is purely cosmetic dressing on a transfer.

The takeaway: no legitimate wallet check ever asks you to sign a Payment. If a “verification” produces a transaction to sign, it is a drain.

Watch the drain — by wallet

Real recordings of the same drain across three wallets. Each shows the identical move: a friendly “verification” prompt that is actually a Payment to the attacker’s wallet.

Crossmarkbrowser extension
Stop it: Just close the tab — the request spam stops. There is no trusted-app entry to remove.
GemWalletbrowser extension
Stop it: Close the tab signed into the attacker, then GemWallet → Settings → Trusted apps → remove it.
Xamanmobile app

What you’re watching

  1. Step 1

    The site pushes a sign request into Xaman, framed as a routine “verification”.

  2. Step 2

    The payload is actually a Payment whose Destination is the attacker’s wallet.

  3. Step 3

    Each approval drains one asset — the highest remaining balance by value first. Declining does nothing, so the attacker re-pushes the next-highest on a loop — the payment-request spam.

Stop it: Xaman → Settings → Third-party apps → remove the app to stop the spam.

Recent drains (live)

Every confirmed drain, newest first — flagged the moment it lands on the ledger.

WhenVictimDrainerSweptTx
4h agorNrx2vh…WcT9rLvNaJK…ZjaA3.0K XRP1D64D8D5
6h agorHPseQp…gJBtrLvNaJK…ZjaA14.4K XRP513FBC24
18h agor3qAzDp…x6iarMC88RE…ki8U133 XRP4681D6F4
19h agorfAJ3dh…KHD2rMC88RE…ki8U506 XRP7DBF021C
19h agor4W4fis…8vu4rMC88RE…ki8U526 XRP8598141C
19h agorsXHyuR…6rucrMC88RE…ki8U202 XRP9AA1191E
21h agorNL618T…qTmUrnbLHZR…yxiG1.6K XRP67131C55
21h agorBSjbS6…2eeKrnbLHZR…yxiG58 XRP0FA0B6D2
21h agorGdgq4U…Sv2yrnbLHZR…yxiG3.1K XRPCD9EC8A8
22h agorsQhir4…NwqurnbLHZR…yxiG53 XRPD66D6F57
1d agorsayASU…vUr1rnbLHZR…yxiG220 XRPF988CC3F
1d agorPzTDFV…UhrsrnbLHZR…yxiG1.3K XRP001425CC
2d agorLbpiHw…dj1JrnbLHZR…yxiG72 XRPDC2F6C32
2d agorpq4hQC…So2QrnbLHZR…yxiG2.1K XRPD97FAD53
2d agorMePZVu…vSeyrpKqbVp…G8ba95 XRP05086274
2d agors7w5aP…4iAernbLHZR…yxiG2.1K XRPCC6530DB
2d agornG22N8…bX5YrnbLHZR…yxiG101 XRPA6E9046B
2d agornb9TNY…2LwbrnbLHZR…yxiG88 XRP5222509C
2d agorfxDZCq…n5Y4rnbLHZR…yxiG517 XRPFBAAA6E3
2d agorNszN35…eVq8rsUWvBx…Vv6n163.5K XRP7EC3235E
3d agorE9UCwS…mGPbrsUWvBx…Vv6n128 XRPBDF10799
3d agorJhGKpz…64dersUWvBx…Vv6n265 XRPD332E8C0
3d agorpjiw2x…12parhT1f6R…7CgZ1.4K XRPC562DDC4
3d agorBeGvxV…KX8rrhT1f6R…7CgZ1.1K XRP0E9D1CDA
3d agorUkcfjW…vEekrhT1f6R…7CgZ113 XRPCD646AFC
4d agorMqR3CZ…vFrkrhT1f6R…7CgZ3.9K XRP06448E53
4d agorNj1UWN…qCbkrhT1f6R…7CgZ228 XRPBEB750BD
4d agoraViByg…UwkZrhT1f6R…7CgZ2.8K XRP54C8FE6E
4d agorL1gUN5…KaxtrhT1f6R…7CgZ331 XRPB12256C0
4d agorwHTGu1…LKB4rhT1f6R…7CgZ51.0K XRP47F8D5B8
4d agorENjdx2…m9ehrhT1f6R…7CgZ865 XRP6F345C82
4d agorGXfAYb…CdEQrhT1f6R…7CgZ163 XRP90B23CFD
4d agorNZAi3q…Z6bWrGmTMJu…DntH3 XRP171DCD60
41d agorswF19L…Ju2yrfj1LJz…8V7m8 XRPF07322E8
42d agorsbUfQL…jzeNrLoVYVN…GkVF645.1K PHNIX1E4C11E8
42d agorsbUfQL…jzeNrLoVYVN…GkVF44 XRP539F7BE8
42d agorJsXx46…H7TerLoVYVN…GkVF51 XRPEB6C5690
42d agorDmpyN2…SborrwP4vSe…ctrn1 USDTBAFA5612
42d agorDmpyN2…SborrwP4vSe…ctrn399 XRPB2F4C8FA
42d agorQhjcaA…EiqjrwP4vSe…ctrn13 XRP50ED8696
43d agor93XvhQ…Ti7CrwP4vSe…ctrn10 XRPFC4BBAC9
43d agorrp8szJ…FcWMrwP4vSe…ctrn12 xPizzaF6054510
43d agorrp8szJ…FcWMrwP4vSe…ctrn5.0K BAYNANA45D65476
44d agor3pioo1…QpE7rfegXyR…DW6b90 XRP2459D447
44d agor4JazZh…mPEerfegXyR…DW6b265 XRP271539FB
44d agornk6sBe…k1AvrNVdQM2…bmH32 XRPF21B1888
44d agorJLC1b6…v2E7rNVdQM2…bmH314.6K XRP84AFDEB4
44d agorDdT4yS…MdfcrNVdQM2…bmH37.85M HBAR6F8B2F8E
44d agorDdT4yS…MdfcrNVdQM2…bmH343.8K CSCB3137AFC
44d agorHe7gbX…rRMxrNVdQM2…bmH338 XRP99381DBE

Drainer wallets

Every destination below is a confirmed drainer wallet on our free, published blocklist. Do not send to, or sign any offer/payment involving, these addresses.

Token sweeps

The drain isn’t XRP-only — it sweeps whatever the victim holds. Confirmed token sweeps:

TokenAmount sweptDrains
HBAR7.85M1
CSC43.8K1
BEAR13.6K1
BAYNANA5.0K1
xPizza121
USDT11
PHNIX645.1K1

What gets flagged

Confirmed drainer wallets are added to a free, verified blocklist that wallets and marketplaces consume. We flag only the attacker’s receiving wallet — a victim who was tricked into signing is never listed.

Free API — block the drainers

No key required. The list is the union of every flagged XRPL address — payment drainers, NFT-phishing scam issuers, and other known scam wallets — so a single integration protects against all of them. Mirror it client-side and reject any Payment or offer to a flagged address before you sign.

1. Flat payment-side blocklist (union of all drainer + scam addresses)
curl https://api.xrpl.to/v1/scams/addresses
2. Check a single counterparty before signing
curl https://api.xrpl.to/v1/scams/check/rNVdQM2AupHsZfGfkHKR4qfPHcLYwwbmH3

Suggested integration: on app load, fetch /v1/scams/addresses once and cache the scamAddressesList; before submitting any Payment or accepting any offer, reject if the counterparty is in the set.

Data is on-chain and updates live as new drains are detected. Snapshot generated 0s ago. This page is informational; it is not financial or legal advice.