Key Highlights
- A crypto user lost about $2.1M in FXRP after following a phishing link from a ChatGPT answer and approving a malicious transaction.
- Blockchain investigator VAL traced the stolen funds through multiple wallets, showing how the assets were moved from FLR to DAI
- Recent phishing attacks show scammers using trusted platforms, Google ads and websites to target crypto users.
A crypto user reportedly lost about $2.1 million in FXRP after following a phishing link that appeared in a ChatGPT response.
According to a Thursday post on X by blockchain investigator VAL, the incident occurred on June 12 after the user asked ChatGPT where to swap sFLR for WFLR and later approved a transaction that allowed the attacker to transfer the tokens.
The victim, who uses the name Alex on X, said he asked ChatGPT the question in Russian. He said the answer included a link that took him to a phishing website. Thinking he had found the right place to make the swap, Alex connected his wallet and signed an “unlimited approve.”
Seconds later, the attacker used the “transferFrom” function to drain about 1.9 million FXRP, worth around $2.1 million at the time. Alex later shared the transaction details and the wallet addresses involved in the theft while asking others to help trace where his funds had gone.
“I asked ChatGPT where to swap sFLR for WFLR. Its answer contained a link — it led to a phishing site,” Alex said in an X post. He added that he signed an “unlimited approve” before the funds were taken.
VAL traces stolen funds across wallets
VAL began following the money after noticing 50 ETH being sent to Tornado Cash from a wallet that had earlier received 120,000 DAI. The investigator found another 380,000 DAI still sitting in the wallet, while about 310,000 DAI had already been split between two other wallets.
The trail went further back. VAL said around 700,000 DAI had been sent to the wallet about two months earlier through 13 transactions. The sending wallets had first swapped FLR for DAI through OpenOcean before sending the funds onward.
The wallet had reportedly been active since April 2026 and had received FLR in different amounts. Some of the funds were moved to other wallets, while another part was bridged to other networks. The assets were then changed into DAI and later into ETH. VAL said 889 ETH in total was sent to one wallet and remained in the wallet when the investigation was reported.
Phishing link no longer appears on ChatGPT
After the $2.1 million drain, the wallet reportedly stopped receiving FLR, but the movement of the stolen funds continued. Alex also said his post about the loss attracted recovery scammers rather than useful help. He warned people not to respond to anyone claiming they could recover the stolen money.
VAL said it checked ChatGPT in several languages and found that the reported phishing link was no longer being returned. The investigator warned users not to trust links from an AI chatbot when dealing with crypto or financial services.
Phishing attack keeps piling up
The incident adds to a growing list of recent crypto phishing attacks. In August, Hyperliquid users allegedly lost about $550,000 after fraudulent Google advertisements directed users to a phishing site. Security researcher DarcyAri flagged the attack and shared three wallet addresses linked to the reported losses.
Another incident that month involved an expired Tornado Cash domain, which was reportedly used to trick a crypto user into losing 1,010 ETH. Together, the incidents show how scammers continue to use trusted names, websites and search tools to get crypto users to sign transactions that can empty their wallets.
In short, these scams show how crypto users can lose large amounts of money through one wrong click or one careless approval.
Also Read: Coldcard Hacker Converts ~20.5 Bitcoin to ETH After Weeks of Inactivity
