
One cryptocurrency user lost approximately $2.1 million in FXRP after clicking a link in a ChatGPT response. According to the victim, he asked in Russian where he could exchange sFLR for WFLR, after which he received the address of a phishing website.
The user connects his crypto wallet to it and signs a transaction with unlimited access to the coins. A few seconds later, the attacker used the transferFrom function to withdraw approximately 1.9 million FXRP. Blockchain researcher VAL then began tracking the flow of funds and discovered linked wallets through which the stolen assets were transferred, converted into DAI and ETH, and transferred between networks. According to the investigation, one of the wallets received a total of 889 ETH.
According to VAL, the phishing link no longer appears in ChatGPT responses after the incident. Researchers tested the service in multiple languages and urged not to obtain links from artificial intelligence because of security concerns, especially when using cryptocurrencies and financial services. The victim himself also warned that the scammers started asking him to “return” the stolen funds.
This case is another example of how dangerous allowing unlimited token cancellations can be. Even clicking on a link that appears to be recommended by a well-known service can lead to a complete loss of funds if the user signs the corresponding transaction without verification.
