A crypto user known as Alex has reportedly lost around 1.9 million FXRP, valued at roughly $2.1 million, after following a phishing link that he said was provided through ChatGPT while he was trying to swap sFLR for WFLR.
The case was highlighted by blockchain investigator VAL on X. According to the account shared publicly, Alex connected his wallet to a site that appeared appropriate for the token swap, then approved a transaction that gave the attacker broad access to the funds.
How the loss allegedly unfolded
Alex said he was searching for a way to convert sFLR to WFLR when ChatGPT directed him to a website that seemed to match the task. After connecting his wallet, he approved what he later described as an unlimited approval transaction.
That approval reportedly allowed the attacker to use transferFrom to move the FXRP out of the wallet within seconds. Alex later posted transaction details and wallet addresses in an effort to help trace the stolen assets.
On-chain tracing points to wider fund movements
VAL said the stolen funds did not remain in a single location. The investigator tracked related activity across multiple wallets and reported notable movements involving DAI, FLR, and ETH alongside the drained FXRP.
The source article does not say whether any of the assets were recovered. It presents the tracing effort as an ongoing attempt to map where the funds moved after the wallet was drained.
Tests reportedly stopped returning the malicious link
After the incident came to light, VAL said tests of ChatGPT prompts in several languages no longer produced the phishing website in responses. That suggests the specific link was no longer being surfaced at the time of the follow-up checks, though the report does not explain why it had appeared earlier.
The episode adds to concerns about using AI-generated responses as a source for crypto transaction links or wallet actions. In this case, the alleged phishing setup appears to have relied on the victim trusting a link that looked legitimate enough to proceed with a live wallet connection and approval.
Warnings after the theft
Alex also cautioned other victims about so-called recovery scammers, who often contact people after a major theft and claim they can retrieve missing funds. Such schemes commonly exploit the urgency and confusion that follow a wallet drain.
VAL compared the case with earlier phishing activity aimed at Hyperliquid users through fraudulent advertisements, which the investigator said resulted in about $550,000 in losses. The next confirmed step in the FXRP case is continued tracing based on the wallet addresses and transaction records that have already been shared publicly.
Source: Coin Edition