Gelalens

Market Prices

Coin Price 24h
BTC Bitcoin
$76,430.7 -2.44%
ETH Ethereum
$2,430.5 -2.86%
SOL Solana
$99.49 -2.28%
BNB BNB Chain
$719.5 -0.28%
XRP XRP Ledger
$1.4 -0.37%
DOGE Dogecoin
$0.0819 -2.38%
ADA Cardano
$0.2025 -2.69%
AVAX Avalanche
$7.45 +0.00%
DOT Polkadot
$0.9852 -2.38%
LINK Chainlink
$11.3 -1.02%

Fear & Greed

69

Greed

Market Sentiment

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

28
03
unlock Arbitrum Token Unlock

92 million ARB released

12
05
halving BCH Halving

Block reward halving event

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$76,430.7
1
Ethereum
ETH
$2,430.5
1
Solana
SOL
$99.49
1
BNB Chain
BNB
$719.5
1
XRP Ledger
XRP
$1.4
1
Dogecoin
DOGE
$0.0819
1
Cardano
ADA
$0.2025
1
Avalanche
AVAX
$7.45
1
Polkadot
DOT
$0.9852
1
Chainlink
LINK
$11.3

🐋 Whale Tracker

🔴
0x5a74...bed0
5m ago
Out
1,199,750 USDT
🟢
0x6e2d...73d1
3h ago
In
442,351 USDC
🔴
0x3bcc...5846
1h ago
Out
4,995.32 BTC

💡 Smart Money

0x62bb...a850
Top DeFi Miner
-$4.5M
80%
0x0c5f...cc47
Top DeFi Miner
-$2.3M
81%
0x7884...6690
Top DeFi Miner
+$1.2M
70%

🧮 Tools

All →
Editorial

ChatGPT Recommended a Phishing Site. 1.9 Million FXRP Gone. Let's Talk About the Real Problem.

CryptoFox

You ask ChatGPT a simple question in Russian: how do I swap sFLR for wrapped FLR. It hands you a link. Looks right. Sceptre dot something. You connect your wallet. You sign. You lose 1,904,513 FXRP — roughly $2.1 million of your own money — before dinner. Typical. Pump, dump, debug. Repeat.

Let's not bury the lead: the attack vector wasn't some zero-day smart contract exploit. It was an AI chatbot recommending a malicious link, plus an unlimited approve signature that drained everything in seconds. The code worked exactly as written. The human trust layer did not.

ChatGPT Recommended a Phishing Site. 1.9 Million FXRP Gone. Let's Talk About the Real Problem.

I've spent years staring at Solidity bytecode, auditing ICOs in 2017 when everyone else was chasing Telegram hype. My instinct is always: show me the transaction, not the tweet. This case is beautiful in its horror because every step is on-chain and verifiable. And what the chain shows is uglier than a simple phishing story. It shows an industrialized phishing operation running for months, a bridge token taking a 1.3% supply hit, and an AI recommendation layer with zero security guardrails. t check.

The Attack Chain, As It Actually Happened

On June 12, 2026, a user named Alex asked ChatGPT how to convert sFLR — Flare's liquid staking token — into wrapped FLR. ChatGPT responded with a link to sceptre.network. The real protocol is sceptre.fi. Same name. Different top-level domain. That's the entire deception.

Alex connected a wallet to the fake site and approved an unlimited spending allowance. Moments before 19:00 UTC on June 12, the attacker's contract called transferFrom and moved all approved FXRP out. Alex never initiated a transfer. He didn't need to. The signature he signed was the transfer.

This is classic approval phishing. EVM developers know this mechanic like they know their own mother's birthday. You sign an approve, granting a spender the right to move tokens. If you set the amount to uint256 max, you've handed over the keys to your entire balance for that token. No expiry. No cap. No escape hatch.

Here's what makes this iteration different: the propagation channel was AI-generated output, not a Google ad, not a Discord DM, not a fake Twitter account. The user trusted ChatGPT because AI assistants have become our neutral, omniscient librarians. Who fact-checks a librarian? Nobody. Gas fees higher than the yield. Typical.

The Infrastructure Was Already Running Before Alex Even Asked

The receiving wallet wasn't spun up for this one victim. On-chain sleuth Val traced the address: its first incoming funds arrived on April 23, 2026 — 50 days before Alex signed his fatal approval. The wallet proceeded to collect at least four different Flare ecosystem tokens. This wasn't a smash-and-grab. This was a professionally operated drainer pipeline, harvesting across multiple protocols and victims.

The timeline matters. Attackers didn't see Alex's ChatGPT query and respond in real time. They built infrastructure, waited, harvested, and let the AI do the distribution. That's the new economic model of crypto theft: drainer-as-a-service meets recommendation-engine poisoning.

It gets worse. BeInCrypto reported earlier this year that drainers had registered fake Uniswap domains and purchased search ads. Same playbook, new front door. The search ad route at least had a paper trail and could be blacklisted. AI recommendation output is dynamic, context-dependent, and generated fresh for every query. You cannot blocklist a stochastic parakeet.

From my audit experience, I can tell you exactly where the technical failure sits: there is no security verification layer between the AI's retrieval and the user's wallet connection. None. Zero. The AI sees a domain with "sceptre" in it and assumes legitimacy. No certificate checking. No contract verification. No is this a known phishing domain lookup. It's like a bank teller who checks your ID but ignores the ski mask.

Let's Talk About the Unlimited Approve Pandemic

We've known about infinite approval abuse for years. In one documented case an Ethereum holder lost $999,999 to a single poisoned signature. Yet wallets continue to present approval requests as innocuous gas-station interactions, and users continue to click without reading the hexadecimal equivalent of a 200-page mortgage.

The availability of approve with a max uint256 is a design choice that has outlived its usefulness. ERC-20 permit exists. Token limits exist. Revocation dashboards exist. The problem is that protocols default to asking for infinite approval because it improves user experience — one signature, no future interruptions — and wallets don't force users to confront what "infinite" means.

Let me translate: approving unlimited spend on a bridge token like FXRP is the economic equivalent of handing a stranger your debit card and PIN because he promised to return it after buying you a coffee. And the stranger turned out to be a chatbot's recommendation.

What's notable here is what didn't break. The Flare bridge itself held. The sFLR wrapping logic held. The vulnerability was entirely in the human layer and the AI layer. This is why the incident is simultaneously less scary and more scary than a protocol exploit. Less scary: no systemic code flaw to patch. More scary: there's no patch for gullibility, and the AI won't stop hallucinating malicious links until someone builds a safety net beneath it.

The Contrarian Angle Nobody Wants to Hear

The contrarian read is uncomfortable: attacks like this will increase AI adoption in crypto, not reduce it.

Think about it. Every new AI-driven trading assistant, every agent-based portfolio manager, every chatbot that promises to simplify DeFi interactions is expanding the attack surface. The 2026 AI-agent experiments I've run — deploying autonomous agents to handle small stablecoin trades — showed me how quickly machine-to-machine transactions become opaque. If a human can't read an approval request, what chance does an agent have? The agents I tested happily signed whatever their reward function suggested. I caught one attempting to approve a test contract I'd never seen before. Not because it was malicious, but because the agent inferred that approving was "what the task required." Code-first verification instinct is a human trait, and current AI systems lack it entirely.

ChatGPT Recommended a Phishing Site. 1.9 Million FXRP Gone. Let's Talk About the Real Problem.

That's the real story here: AI is not the shield against crypto complexity. It's the newest attack amplifier. The market narrative says AI agents will democratize DeFi. This incident says AI agents will democratize theft. The average user doesn't read contract bytecode. Now they also can't trust their AI assistant to read it for them.

Another blind spot: the stolen FXRP represents about 1.3% of total supply. That sounds manageable. But the wallet has been operating since April and received multiple token types. Alex may be one of many victims, and $2.2 million may be the floor, not the ceiling. If this same infrastructure hit five other users quietly, the real drain could be multiples of the reported number. We don't know because most approval phishing victims don't go viral. They just check their wallet one day and discover it's empty.

Where the Regulatory and Governance Gaps Fester

OpenAI, when asked about a related AI-agent incident, responded that it couldn't comment on reports it hadn't reviewed. That's corporate boilerplate, but it reveals a structural vacuum: no regulatory framework currently assigns liability when an AI model recommends a malicious link that results in financial loss.

Is OpenAI responsible? Legally, probably not. Ethically, the conversation is just beginning. If a human financial advisor recommended a fraudulent investment, they'd lose their license. If an AI does it, the response is a shrug and a promise to "improve safety."

The same governance vacuum applies to Flare. The protocol didn't fail — a user fell for a fake domain whose real twin lives on the same ecosystem. But Flare's security reputation pays the price. I've seen this pattern before: protocol code is fine, user collateral evaporates, and the ecosystem's TVL charts look like a heartbeat monitor flatlining. Short-term trust damage is real, even if long-term fundamentals survive.

What would actually help? Three things. First, wallet developers need to enforce approval limits by default, or at minimum present a plain-English risk warning when a dApp requests infinite allowance. Second, AI providers need to integrate link safety scanning into their retrieval pipelines — a basic filter that checks domains against known phishing blocklists before recommending them. This isn't impossible. It's a weekend project for a competent team. The fact that it hasn't been done is a failure of prioritization, not engineering. Third, users need to treat AI recommendations like they treat a stranger's advice at a bar: friendly, plausible, and absolutely unverified.

The Market Can't Price This Yet

The published loss is approximately $2.1 million for Alex, spread across $2.2 million total from the same infrastructure. That's statistically trivial in a bull market where a single whale wallet sneezes and $50 million moves. FXRP's market impact will likely be muted by the sheer time lag — the attack happened in June, this reporting surfaced roughly three months later.

But the narrative impact is different. This is an early-stage story about AI-assisted user compromise, and early-stage stories accumulate momentum. If three more similar cases surface within the next quarter, watch how quickly "AI recommendation phishing" becomes a dedicated security category, complete with new tooling startups and a conference panel or three. The opportunity is glaring: a Chrome extension that strips suspicious links out of ChatGPT responses would have a waiting list tomorrow.

The next big crypto security business is not another audit firm. It's a verification layer between AI output and financial action. The infrastructure already exists for contracts and tokens. Build it for recommendations, and you own a new category.

Beyond the Headlines: What I'm Watching Now

Let's talk about what happens next, because that's the part the press releases won't cover.

First, watch whether similar attacks emerge on other AI platforms. ChatGPT isn't the only assistant recommending contracts. Claude, Gemini, and specialized crypto AI agents can all be fed poisoned source material. The researcher Nightingale documented an OpenAI agent performing about 15,000 edits on DseWiki, and a larger "jailbreak" event followed in July. The trend line is unambiguous: AI systems are becoming more autonomous and less supervised.

Second, watch whether the Flare ecosystem responds with actual security tooling or just a blog post about "being careful." If Flare ships a native approval manager with expiry dates and per-token limits, that's a signal that ecosystem leaders understand the gravity. If they release a statement about user education, we'll see the same attack succeed on Flare again within six months.

Third, monitor that receiving wallet. A single transfer of 500,000+ FXRP to an exchange would signal the attacker's exit liquidity phase, and FXRP could face real selling pressure. The supply hit is only 1.3%, but a concentrated dump from a malicious actor doesn't behave like a rational holder rotating positions. It behaves like a thief trying to get out before the trail gets cold.

The Honest Takeaway

I've audited enough contracts and watched enough retail investors lose everything to stop believing in silver bullets. This incident won't be the last of its kind. It won't even be the largest. What it represents is a handshake between two of crypto's weakest security assumptions: AI output is trustworthy, and unlimited approvals are harmless.

Both are false. Both are fixable. Neither will be fixed before more money disappears.

The next time you ask an AI assistant for a DeFi tutorial, wait. Wait before you click. Check the domain with your own eyes. Look at the fucking contract. And if something asks for infinite approval, remember: a stranger on the blockchain is still a stranger, whether the recommendation came from a pair of sneakers or a polite blue chatbot. The chain never lies. It just doesn't care that you trusted someone else to read it for you.

Pump, dump, debug. Repeat. That's the industry. The only question is whether you learn the debug part before the dump part takes your portfolio.

t check.

ChatGPT Recommended a Phishing Site. 1.9 Million FXRP Gone. Let's Talk About the Real Problem.

I'm watching the wallet. I'm watching Flare's response. And I'm keeping my own gas fees far away from any AI-recommended "official" link. You should too.