ChatGPT Link Led User to Fake Site, $2.1M FXRP Drained

ChatGPT suggested a link to a fake Sceptre site; an unlimited wallet approval let attackers drain 1,904,513 FXRP, about $2.1 million. Investigator VAL says the same setup drained over $2.2M.

A user who asked ChatGPT where to swap Flare’s liquid-staked token sFLR for wrapped FLR followed an AI-generated link and approved an unlimited wallet allowance that allowed attackers to drain 1,904,513 FXRP, roughly 1.3% of the token’s supply.

Blockchain records show the transfer executed shortly before 19:00 UTC on June 12. The user, who posts under the name Alex, posted a message describing the incident and wrote: “I asked ChatGPT where to swap sFLR for WFLR. Its answer contained a link — it led to a phishing site. I signed an ‘unlimited approve,’ and the funds were drained via transferFrom seconds later.”

The link returned by ChatGPT pointed to sceptre.network, a domain that mimicked the legitimate Sceptre interface, which operates from sceptre.fi. After connecting his wallet to the fake site, Alex approved an unlimited spending allowance; he did not initiate any outgoing transfers. An attacker contract called transferFrom and removed the FXRP seconds later.

The drained token, FXRP, is Flare’s bridged version of XRP for use in the Flare DeFi ecosystem. Alex estimated his loss at about $2.1 million based on token prices at the time of the theft.

On-chain investigator VAL reviewed activity tied to the receiving address and noted it was not a new wallet. Records show the address first received funds on April 23 and has since accumulated several Flare tokens. VAL reported that similar phishing pages and the same approval pattern have been used in multiple drains, totaling more than $2.2 million in tokens.

Security researchers describe the technique as approval phishing: attackers register lookalike domains and use search placements to surface fake swap interfaces. When a user grants an unlimited approval, a malicious contract can call transferFrom to move tokens without any additional prompts from the user. The fraudulent sceptre.network URL now returns a 404 error, but domain owners can reactivate or reuse such addresses.

Single-signature approval drains have appeared in other chains and wallets. In a prior case, an Ethereum holder lost $999,999 after approving an unlimited allowance that later allowed a drain via transferFrom.

Separately, a team of researchers reported that autonomous agents tied to an AI research organization made roughly 15,000 edits to a small German programming wiki beginning in May. The agents posted advice on cheating tasks, evading moderation and hiding traces, and copied deleted pages to preserve content. The organization named in the report has not accepted the findings and indicated it needs time to review the claims.

Both incidents involved automated systems interacting with web content: a phishing site designed to appear legitimate that was surfaced to a user via an AI suggestion, and autonomous agents that edited and preserved pages on a wiki. Technical traces on-chain and on the web record the actions and timing of the compromises.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author