Web3: Phishing emails impersonating Ledger updates lead to the theft of 400,000 XRP.
Coinpedia
07-28 02:33
Ai Focus
Phishing emails impersonating Ledger updates resulted in the theft of approximately 400,000 XRP from one holder.
Helpful
No.Help

An XRP holder lost approximately 400,000 XRP after mistakenly trusting an update email impersonating Ledger. He was on vacation processing emails when the attacker tricked him into entering his wallet information under the guise of a device upgrade, and then transferred his assets.

The attack occurred on holiday night.

The theft reportedly occurred on Easter night. The victim had approximately 400,000 XRP stored in a hardware wallet. The email was disguised as an update notification from Ledger, resembling a typical software upgrade notification.

After clicking the link, the victim filled in their wallet information as prompted on the page. The attacker then used the obtained credentials to transfer the assets, and the XRP in the hardware wallet was quickly emptied.

Fake update links to trick people into giving them credentials

The report noted that these phishing emails have become increasingly realistic in recent years, often using "security updates" or "device upgrades" to lure users into taking action. Even those with some security experience may misjudge the source in everyday situations.

The key issue in this incident is not the hardware wallet itself, but rather that the attackers forged communication channels to trick users into handing over sensitive information. Once the recovery phrase or related verification information is leaked, assets could be quickly transferred away.

Another 50,000 XRP were unaffected.

The victim also had approximately 50,000 XRP stored in a separate escrow account, and these funds were not stolen. This was because the account had an additional verification process, requiring callback confirmation and voice verification before any transaction could proceed.

This also shows that if large positions are combined with a stricter approval mechanism, even if a phishing attack occurs, the losses caused by a single misoperation can be reduced to some extent.

Self-hosting still requires additional protection.

The report argues that this incident does not negate self-hosting itself, but rather demonstrates once again that while self-hosting can reduce reliance on third-party platforms, it cannot automatically prevent social engineering and phishing attacks.

For holders of digital assets such as XRP and Bitcoin, any sudden upgrade notifications, verification requests, or email links must be verified individually, and sensitive wallet information should not be entered in the email redirect page.

Tip
$0
Like
0
Save
0
Views 349
WalletJYS reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
web3: XRP Ledger upgrade passes final vote, multiple features to be launched
An upgrade to XRP Ledger has passed the final vote, and features such as bulk transactions, privacy transfers, and institutional lending will be rolled out later.
Coinpedia
·2026-07-27 02:11:17
300
Web3: Coldcard wallet vulnerability leads to the theft of 594 bitcoins.
Coldcard hardware wallets were found to have a key generation flaw, allowing attackers to steal approximately 594 bitcoins within 25 minutes.
CoinDesk
·2026-07-31 13:25:06
990
Web3: Coldcard key vulnerability leads to the theft of approximately 594 bitcoins.
Coinkite claims that the Coldcard seed generation vulnerability has resulted in the theft of approximately 594 bitcoins, and attackers may have used AI to discover the problem.
Decrypt
·2026-07-31 17:25:06
883
Web3: The Thai Securities and Exchange Commission accuses Bitkub of concealing a $50 million theft.
The Thai Securities and Exchange Commission has accused Bitkub of concealing a 2021 cyberattack that resulted in approximately $50 million in losses. The case has been transferred to the police for investigation.
CoinDesk
·2026-07-27 21:41:55
558
Web3: The Thai Securities and Exchange Commission (SEC) has filed a lawsuit against Bitkub in connection with a $47 million theft.
The Securities and Futures Commission of Thailand has filed a criminal complaint regarding Bitkub's disclosures following the 2021 theft, and the case is now being handled by the police and prosecutors.
Decrypt
·2026-07-27 18:02:06
575