
A fake Ripple-style website promising rewards for long-term XRP holders adds to a broader phishing wave that has also hit Xaman and other XRP-linked brands.
A phishing campaign targeting XRP holders has expanded with a fake Ripple-style website that mimics the company's branding and promises unspecified rewards for investors who "never sold," before steering users to a wallet-draining link. David Schwartz responded to a screenshot of the site on X with a blunt warning, calling it a scam. The latest lure builds on a wider wave of attacks across the XRP Ledger ecosystem in early August. Attackers have used cloned websites, impersonator accounts and social-engineering tactics to pressure users into connecting wallets, approving malicious transactions or disclosing wallet credentials. On Aug. 1-2, Xaman wallet's verified X account was compromised and used to promote a fake "XMN" token, prompting Wietse Wind to say there is no token, there never has been one, and there never will be one. Earlier warnings had already spread after a fake Ripple account promoted a fabricated "XRP Holder Tiers" program, while Xora Finance and Doppler Finance cautioned that scammers were cloning trusted XRP-related brands and impersonating support staff. Joren Lundgren, Xora Finance founder, said a sophisticated operation is under way and warned that a group of South Korean scammers is targeting the XRP community specifically. Seoul police are also probing fake staking sites after a fake Flare Network staking platform allegedly took 3.4 million XRP from 71 investors, with estimated losses cited at more than 20 billion won, or about $13.4 million. The attacks highlight a familiar crypto-fraud pattern: rather than exploiting a blockchain flaw, scammers rely on social engineering and the irreversible nature of signed transactions to get victims to authorize the theft themselves.