An XRP holder lost 14,646 XRP, worth about $16,800, after approving a fraudulent payment request on the XRP Ledger. Crypto commentator Xaif Crypto said the incident was not tied to a software flaw or protocol issue. It was a social engineering attack, with the victim persuaded to authorize the transfer personally.
Fake verification language made the request look credible
Details shared by Xaif Crypto show that the payment request carried a promise of a 10% monthly reward. It also included a memo reading “Safe XRPL verify message.” That wording gave the impression that the transaction had already passed some kind of security check. In reality, the memo was part of the deception, crafted to make the request appear legitimate enough for the user to proceed.
Once approved, the XRP was sent to the destination wallet. A later review found that the receiving address had already been flagged as fraudulent on the XRPL explorer. The warning existed, but the transfer still went through, leaving the holder with a substantial loss.
Attackers are leaning on user trust instead of technical exploits
The case highlights a tactic that keeps surfacing in crypto scams. Rather than targeting vulnerabilities in blockchain infrastructure, scammers are attaching misleading context to transactions and relying on users to trust it. Terms like “safe” and “verify” can create a false sense of assurance. That can be enough to pull attention away from destination addresses, wallet alerts, and other critical details.
Reward-based lures remain central to this playbook. A promise of recurring returns can push users to act quickly, and speed often replaces scrutiny. On-chain transfers make the damage worse. Once a blockchain transaction is confirmed, reversing it is generally not an option, which makes asset recovery extremely difficult.
Similar scam attempts have already hit the XRP ecosystem
The report connects this incident to earlier warnings involving XRP wallets. 36Crypto previously reported that Xaman founder Wietse Wind had cautioned users about unsolicited NFT offers sent to random XRPL addresses. According to Wind, scammers watched legitimate NFT listings and offers, then created copies through separate wallets.
Those cloned assets were designed to look authentic and draw users into interacting with fraudulent offers. Anyone who failed to verify the originating wallet address risked engaging with counterfeit NFTs and exposing funds. The latest loss of 14,646 XRP shows the same pattern from a different angle: the method may shift, but the scam still depends on convincing users that a malicious transaction is safe.

