[DigitalToday reporter Yoonseo Lee] A fake website that closely imitates Ripple’s official site has emerged, spreading phishing attacks targeting XRP holders.
On Aug. 5 (local time), blockchain media outlet U.Today reported that David Schwartz (데이비드 슈워츠), known as Ripple’s former chief technology officer (CTO), issued an immediate warning on X, formerly known as Twitter, calling a screenshot of the site posted there “a scam.”
The site in question looks like a page Ripple built itself. It is styled to resemble the real site, with a dark blue design, brand font, logo and even a “Buy XRP” button in the top right. The wording, however, is crafted to target the mindset of long-term holders. A top banner reads, “Something is coming for those who have never sold,” followed by, “I can’t say what it is, but a reward for patience.”
The site drew users in by emphasizing scarcity and urgency. It appeared to offer investors a limited opportunity, but in reality it was structured to prompt users to click a “Get Early Access” button and then approve a transaction from their wallet. Once the user approves it, the XRP balance in the wallet is immediately drained.
This case was reported to be part of a string of phishing attacks that continued across the XRP Ledger ecosystem in early August. Attackers were said to have used a leaked investor database and tactics to bypass spam filters. A key feature was the precise targeting of long-term holders’ loyalty and reward psychology.
On Aug. 1 and 2, Xaman, a popular wallet previously known as Xumm, was also targeted. As promotional posts for an “XMN” token, made to look as if the team had issued them, spread widely, the group immediately denied them. Xaman founder Wietse Wind (위체 빈드) said, “That token does not exist. It never existed in the past, and it never will.”
The core tactic in recent attacks is closer to social engineering than a technical vulnerability in the blockchain itself. Attackers create plausible designs, then cloud users’ judgment with pressure messages along the lines of “grab it before the opportunity disappears,” ultimately getting users to press the confirmation button themselves.
XRP Ledger transactions cannot be reversed once approved. That means funds cannot be recovered if a user signs a transaction directly on a phishing site or enters a secret phrase. That is also why Schwartz moved quickly to warn users.
Ripple does not operate a private rewards program, hidden support fund or separate pool for “those who have never sold.” This case again confirmed that any page promoting such offers is a scam. For XRPL ecosystem users, checking official channels and reviewing requests before approving wallet transactions are likely to remain the most important defensive measures for the time being.
pic.twitter.com/QuXUC8mtDk