LIVE MARKET DATA THU 13 AUG 2026 UTC [ VIEW ALL COINS ]
// Regulation

On-chain: XRPL NFTokenAcceptOffer exploit drains $15K as fraudulent NFT mints scale daily

Bithomp flags a native-function phishing pattern on XRPL: one wallet lost $15K via NFTokenAcceptOffer, part of a broader $17B 2026 scam-loss backdrop.

Tomas Keller · ·upd ·2 min read
On-chain: XRPL NFTokenAcceptOffer exploit drains $15K as fraudulent NFT mints scale daily

A single XRP Ledger wallet lost approximately $15,000 in a single transaction that exploited the network’s native NFTokenAcceptOffer function — no malware, no key compromise. XRPL explorer Bithomp flagged the address after it accepted an offer on an NFT labeled “Ripple Payout Token #7357,” which triggered a one-way balance transfer to an attacker-controlled wallet.

Transaction mechanics: signing is the vulnerability

The mechanism requires no external tooling. A wallet receives an NFT designed to look like a claimable reward; signing NFTokenAcceptOffer to “accept” it instead authorizes a large outbound XRP transfer. The NFT itself has zero utility post-execution — it exists solely as the trigger for the malicious signature request.

Bithomp’s data shows attackers minting hundreds of these tokens per day, a volume made economically viable by XRPL’s low per-transaction fees. Observed labels include “Securing XRPL Proof,” “XRP Earning Permit,” “XRP Cashback Card,” “Ripple Benefit Badge,” “Boosting Ripple Card” and “Ripple Grant Voucher” — all engineered to mimic official or time-sensitive payouts.

Distribution runs on two tracks that converge on the same signature request: direct airdrops to active XRPL addresses, and social-media promotion driving users to external sites that request wallet connection before surfacing the NFTokenAcceptOffer prompt.

Scaling context: scam losses hit record territory

The incident sits inside a much larger loss dataset. An FBI report puts 2025 US crypto-scam losses above $11.3 billion, the largest single fraud category tracked domestically. A separate Chainalysis estimate for 2026 puts global crypto scam losses at a record $17 billion, with impersonation schemes identified as the most common vector and generative-AI tooling cited as a factor outpacing investigator and platform response capacity.

This is not XRPL’s first signing-based phishing wave — a prior campaign used fake wallet “verification” prompts to extract comparable unauthorized transfers. The recurrence suggests threat actors are iterating specifically on XRPL’s NFT-offer and transaction-signing flows rather than migrating to alternative chains.

Positioning note

For active wallets: any unsolicited NFT should be treated as untrusted, and offers framed as payouts, cashback, grants or verification steps warrant full transaction-detail review before signing — the exploit lives entirely inside the signature, not the token.

Sources

More Regulation