On-chain: XRPL NFTokenAcceptOffer exploit drains $15K as fraudulent NFT mints scale daily
Bithomp flags a native-function phishing pattern on XRPL: one wallet lost $15K via NFTokenAcceptOffer, part of a broader $17B 2026 scam-loss backdrop.

A single XRP Ledger wallet lost approximately $15,000 in a single transaction that exploited the network’s native NFTokenAcceptOffer function — no malware, no key compromise. XRPL explorer Bithomp flagged the address after it accepted an offer on an NFT labeled “Ripple Payout Token #7357,” which triggered a one-way balance transfer to an attacker-controlled wallet.
Transaction mechanics: signing is the vulnerability
The mechanism requires no external tooling. A wallet receives an NFT designed to look like a claimable reward; signing NFTokenAcceptOffer to “accept” it instead authorizes a large outbound XRP transfer. The NFT itself has zero utility post-execution — it exists solely as the trigger for the malicious signature request.
Bithomp’s data shows attackers minting hundreds of these tokens per day, a volume made economically viable by XRPL’s low per-transaction fees. Observed labels include “Securing XRPL Proof,” “XRP Earning Permit,” “XRP Cashback Card,” “Ripple Benefit Badge,” “Boosting Ripple Card” and “Ripple Grant Voucher” — all engineered to mimic official or time-sensitive payouts.
Distribution runs on two tracks that converge on the same signature request: direct airdrops to active XRPL addresses, and social-media promotion driving users to external sites that request wallet connection before surfacing the NFTokenAcceptOffer prompt.
Scaling context: scam losses hit record territory
The incident sits inside a much larger loss dataset. An FBI report puts 2025 US crypto-scam losses above $11.3 billion, the largest single fraud category tracked domestically. A separate Chainalysis estimate for 2026 puts global crypto scam losses at a record $17 billion, with impersonation schemes identified as the most common vector and generative-AI tooling cited as a factor outpacing investigator and platform response capacity.
This is not XRPL’s first signing-based phishing wave — a prior campaign used fake wallet “verification” prompts to extract comparable unauthorized transfers. The recurrence suggests threat actors are iterating specifically on XRPL’s NFT-offer and transaction-signing flows rather than migrating to alternative chains.
Positioning note
For active wallets: any unsolicited NFT should be treated as untrusted, and offers framed as payouts, cashback, grants or verification steps warrant full transaction-detail review before signing — the exploit lives entirely inside the signature, not the token.