An XRP holder lost approximately 400,000 XRP after mistakenly trusting an update email impersonating Ledger. He was on vacation processing emails when the attacker tricked him into entering his wallet information under the guise of a device upgrade, and then transferred his assets.
The attack occurred on holiday night.
The theft reportedly occurred on Easter night. The victim had approximately 400,000 XRP stored in a hardware wallet. The email was disguised as an update notification from Ledger, resembling a typical software upgrade notification.
After clicking the link, the victim filled in their wallet information as prompted on the page. The attacker then used the obtained credentials to transfer the assets, and the XRP in the hardware wallet was quickly emptied.
Fake update links to trick people into giving them credentials
The report noted that these phishing emails have become increasingly realistic in recent years, often using "security updates" or "device upgrades" to lure users into taking action. Even those with some security experience may misjudge the source in everyday situations.
The key issue in this incident is not the hardware wallet itself, but rather that the attackers forged communication channels to trick users into handing over sensitive information. Once the recovery phrase or related verification information is leaked, assets could be quickly transferred away.
Another 50,000 XRP were unaffected.
The victim also had approximately 50,000 XRP stored in a separate escrow account, and these funds were not stolen. This was because the account had an additional verification process, requiring callback confirmation and voice verification before any transaction could proceed.
This also shows that if large positions are combined with a stricter approval mechanism, even if a phishing attack occurs, the losses caused by a single misoperation can be reduced to some extent.
Self-hosting still requires additional protection.
The report argues that this incident does not negate self-hosting itself, but rather demonstrates once again that while self-hosting can reduce reliance on third-party platforms, it cannot automatically prevent social engineering and phishing attacks.
For holders of digital assets such as XRP and Bitcoin, any sudden upgrade notifications, verification requests, or email links must be verified individually, and sensitive wallet information should not be entered in the email redirect page.











