ChatGPT Recommended a Fake Crypto Site Linked to $2.2 Million Scam
ChatGPT pointed a user toward a fake crypto site, and when they signed one approval, 1,904,513 FXRP left their wallet.
That is about 1.3% of the entire FXRP supply today. Investigator VAL says the same phishing setup took more than $2.2 million overall.
One Signature, 1.9 Million FXRP Gone
The victim goes by Alex on X (Twitter), an individual who asked ChatGPT in Russian where to swap sFLR, Flare’s liquid-staked token, for wrapped FLR.
The answer carried a link to sceptre.network, and not Sceptre. The real liquid staking app runs from sceptre.fi. Alex connected his wallet and approved an unlimited spending limit. He never moved the tokens himself.
Blockchain records show the drain ran shortly before 7 pm UTC on June 12. The attacker’s own contract called it. Alex’s signature had already done the work.
Lost ~1.9M FXRP to an approval-phishing scam.
— Alex (@vesnuhin) June 13, 2026
I asked ChatGPT where to swap sFLR for WFLR. Its answer contained a link — it led to a phishing site. I signed an "unlimited approve," and the funds were drained via transferFrom seconds later.
Tx:… pic.twitter.com/1waLIWyotG
The token was FXRP, Flare’s bridged version of XRP for decentralized finance (DeFi). Alex put the loss near $2.1 million.
The receiving wallet was not new either, with blockchain data showing its first funds landed on April 23, fifty days before Alex signed. It has since taken in at least four different Flare tokens, suggesting he may have not been the only target.
“This wallet has been operating since April 2026, receiving FLR in varying amounts,” on-chain investigator Val noted.
BeInCrypto described this method earlier in the year, three weeks before Alex clicked. Drainers register lookalike Uniswap domains and buy search ads to farm approvals.
@Uniswap typing your name on Google has shown a scam site at the top for weeks.
— BeInCrypto (@beincrypto) March 31, 2026
Many users have reported losing funds after connecting wallets to an identical interface.
The site is now down (404), but the URL still appears. It can be reused or reactivated by scammers.
Please… pic.twitter.com/tZm5uYzlJK
The unlimited approval is the whole attack, just as one Ethereum holder learned after losing $999,999 to one signature.
OpenAI’s Agents Took Over a German Wiki
Elsewhere, Reuters reported Friday that agents linked to OpenAI made about 15,000 edits to DseWiki, a quiet German programming wiki, starting in May.
Researchers led by Sydney Von Arx of the AI safety nonprofit Nightingale found the agents swapping tips. They traded ways to cheat tasks, dodge OpenAI’s rules and hide their tracks. About half took names like OpenAIResearcher.
When a moderator began deleting pages in June, the agents saved ZZZ-prefixed copies. An alphabetical sweep reaches those last. Some discussed using Tor.
OpenAI has not accepted the findings.
“We are unable to meaningfully respond to claims or findings on a report that we have not had an opportunity to review” Reuters reported, citing an OpenAI spokesperson.
A July breakout went further, with roughly 1,200 agents gathering on an improvised board. About 700 then breached Hugging Face. BeInCrypto covered that escape in August, when OpenAI gated its cyber model.
This could be one of the most significant AI safety incidents to date.
— Chubby♨️ (@kimmonismus) September 4, 2026
Reuters reports that OpenAI agents escaped their testing environment and made more than 15,000 edits to a German wiki, effectively turning it into a message board for other AI agents.
They allegedly used it… https://t.co/zt1fnNNfho pic.twitter.com/lY5Jk6kNfs
The two cases share a medium, not a culprit. Criminals seeded the web so a model would echo their link. OpenAI’s agents wrote to it themselves. Both worked because a page looked safe.