Common XRP Phishing Scams and How to Avoid Them
Giveaway scams get the most attention because they're loud and public, but phishing is quieter and arguably more effective — it doesn't need you to fall for a "double your XRP" pitch, just to make one careless click on an otherwise ordinary-looking day.
Fake wallet and exchange login pages
A near-perfect copy of a real wallet or exchange login page, reached through:
- A sponsored search ad ranked above the real site, using a domain that's one or two characters off (a swapped letter, an extra hyphen, a different top-level domain).
- A link in an unsolicited message — email, DM, or a comment — claiming your account needs "verification" or has a security issue.
The page looks identical to the real thing. The only difference is the domain in the address bar, which is exactly why checking it — every time, not just the first time — matters more than how the page looks.
Malicious browser extensions
A browser extension claiming to be a wallet, a price tracker, or a "portfolio manager" that actually reads clipboard contents or intercepts what you type. Some are outright fake from the start; others are legitimate extensions that changed hands and had malicious code added in an update. Install only what you need, from official extension stores, and periodically review what's installed rather than assuming it's still safe because it once was.
Fake support that messages you first
A "support agent" who DMs you first — on Telegram, Discord, or X — after you post a question in a public channel, offering to help resolve it privately. Real support teams for legitimate platforms essentially never initiate a DM to solve your problem; the request to "move to DMs" is itself the red flag. The eventual ask is almost always the same: your seed phrase, private key, or remote access to your screen, framed as necessary to "diagnose" or "verify" your account.
Drainer approvals
A newer pattern: a site or dApp asks you to "connect" and approve a transaction that looks routine but actually grants broad spending permission over your assets, executed the moment you sign. This is why understanding what you're approving — not just clicking "confirm" out of habit — matters. If a signature request doesn't clearly and specifically describe what it's authorizing, don't sign it.
Practical prevention
- Bookmark the real URLs for anything you use regularly and navigate from the bookmark, instead of searching or clicking ads each time.
- Never enter a seed phrase or private key into a website, ever, regardless of how official it looks or what "verification" is claimed to require it. No legitimate service needs it.
- Treat unsolicited DMs offering help as a red flag, not a convenience.
- Read what you're approving before signing anything, and reject approval requests you don't fully understand.
This site never asks for a wallet connection, private key, or seed phrase anywhere — our Wallet Lookup and Scam Checker tools only ever take a public address as input, which is information that's already visible to anyone on the XRP Ledger. If a site claiming to be a "checker" or "lookup" tool asks for more than that, treat it the same as any other phishing attempt.