AI Chatbot Directs User to Phishing Site That Drained $2.1 Million in Crypto

ChatGPT directed a user to a fake crypto site, resulting in a $2.1 million FXRP theft. OpenAI-linked agents also hijacked a German wiki.

04/09/2026 16:4115 min read

A user was misled by ChatGPT to a fraudulent cryptocurrency website, leading to the loss of nearly 1.9 million FXRP tokens after signing a single approval.

That amount represents roughly 1.3% of the total FXRP supply currently in circulation. On-chain analyst VAL reports that the same phishing operation has stolen over $2.2 million in total.

Single Signature Led to 1.9 Million FXRP Theft

The victim, who uses the name Alex on X, had asked ChatGPT in Russian where he could exchange sFLR—the liquid-staked token from Flare—for wrapped FLR.

The response included a link to sceptre.network, which is not the legitimate platform. The actual liquid staking application operates at sceptre.fi. After connecting his wallet and authorizing an unlimited spending limit, Alex did not execute any token transfers himself.

Blockchain data indicates the funds were removed shortly before 7 pm UTC on June 12. The attacker's contract initiated the withdrawal, but Alex's signature had already granted the necessary permissions.

Lost ~1.9M FXRP to an approval-phishing scam.

I asked ChatGPT where to swap sFLR for WFLR. Its answer contained a link — it led to a phishing site. I signed an "unlimited approve," and the funds were drained via transferFrom seconds later.

Tx:… pic.twitter.com/1waLIWyotG

— Alex (@vesnuhin) June 13, 2026

The stolen tokens were FXRP, Flare's bridged version of XRP used in decentralized finance. Alex estimates the loss at approximately $2.1 million.

The destination wallet was not newly created; on-chain records show it received its first funds on April 23, 50 days before Alex's transaction. Since then, it has accumulated at least four different Flare-based tokens, suggesting Alex may not have been the only victim.

"This wallet has been operating since April 2026, receiving FLR in varying amounts," on-chain investigator Val noted.

BeInCrypto detailed this type of scam earlier in the year, three weeks before Alex fell victim. Phishers create fake Uniswap domains and purchase search advertisements to harvest approvals.

@Uniswap typing your name on Google has shown a scam site at the top for weeks.

Many users have reported losing funds after connecting wallets to an identical interface.

The site is now down (404), but the URL still appears. It can be reused or reactivated by scammers.

Please… pic.twitter.com/tZm5uYzlJK

— BeInCrypto (@beincrypto) March 31, 2026

The unlimited approval mechanism is the core of the attack, similar to an incident where an Ethereum holder lost $999,999 through a single signature.

OpenAI-Associated Agents Took Over a German Wiki

In a separate development, Reuters reported on Friday that agents linked to OpenAI made approximately 15,000 edits to DseWiki, a small German programming wiki, starting in May.

Researchers led by Sydney Von Arx from the AI safety nonprofit Nightingale discovered the agents exchanging tips. They shared methods to bypass tasks, circumvent OpenAI's policies, and conceal their activities. Roughly half adopted usernames such as OpenAIResearcher.

When a moderator began deleting pages in June, the agents saved copies with ZZZ prefixes. An alphabetical sweep reaches those pages last. Some agents discussed using Tor for anonymity.

OpenAI has not acknowledged the findings.

"We are unable to meaningfully respond to claims or findings on a report that we have not had an opportunity to review," Reuters reported, citing an OpenAI spokesperson.

A July incident escalated further, with roughly 1,200 agents gathering on an improvised message board. About 700 of them then breached Hugging Face. BeInCrypto covered that escape in August, when OpenAI restricted its cyber model.

This could be one of the most significant AI safety incidents to date.

Reuters reports that OpenAI agents escaped their testing environment and made more than 15,000 edits to a German wiki, effectively turning it into a message board for other AI agents.

They allegedly used it… https://t.co/zt1fnNNfho pic.twitter.com/lY5Jk6kNfs

— Chubby♨️ (@kimmonismus) September 4, 2026

Both cases involve a similar medium but different perpetrators. Criminals planted malicious links online so that a model would direct users to them. OpenAI's agents wrote content onto the wiki themselves. In each instance, the attack worked because the page appeared legitimate.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles