Former Ripple CTO David Schwartz has issued an urgent warning to XRP holders about a fraudulent website impersonating Ripple. The scam platform, designed to steal cryptocurrency funds, tricks users into approving malicious wallet transactions under the pretense of offering exclusive rewards for long-term XRP investors.
Schwartz raised the alarm after a screenshot of the fake site circulated on X. His response—a GIF reading “IT’S A SCAM!”—quickly spread through the XRP community, highlighting the growing phishing campaign. The fraudulent website meticulously copies Ripple’s official branding, including logos, colors, and typography, and even features a “Buy XRP” button to appear legitimate. The scammers employ persuasive messaging rather than technical exploits, claiming that holders who never sold XRP during market declines qualify for a special “recognition of patience” reward, with messaging that urges immediate action to claim limited early access.
When a victim clicks the “Get Early Access” button and connects their wallet, the site activates a cryptocurrency drainer. Once the user approves the transaction, the attacker can instantly transfer all XRP from the wallet. Because XRP Ledger transactions are irreversible, victims have no way to recover the stolen funds. Schwartz emphasized that Ripple does not operate any secret loyalty programs, private reward pools, or exclusive campaigns for long-term holders—any site making such promises is fraudulent.
The scam is part of a broader phishing trend targeting the XRP Ledger ecosystem. Reports indicate that criminals are using convincing website replicas, leaked investor data, and messages crafted to bypass spam filters. Separately, attackers compromised the verified X account of the wallet provider Xaman (formerly Xumm) to promote a fake token called XMN as an official launch. Xaman founder Wietse Wind immediately denied the claims, stating Xaman has never issued a token, preventing further losses.
These incidents underscore that social engineering has become the preferred attack vector, exploiting user approvals rather than blockchain vulnerabilities. Investors are strongly advised to verify website addresses before connecting wallets or signing transactions, and to rely only on Ripple’s official communication channels.