TLDR $3M in XRP stolen after investor imported seed into Ellipal mobile app. Ellipal confirmed wallet became hot once seed was added to mobile app. ZackXBT traced stolen funds through cross-chain swaps to Tron wallets. Recovery is unlikely after XRP was funneled through OTC and swap tools. A U.S. investor has claimed he lost over [...] The post XRP Theft Claims Spark Online Investigation and Wallet Security Questions appeared first on CoinCentral.TLDR $3M in XRP stolen after investor imported seed into Ellipal mobile app. Ellipal confirmed wallet became hot once seed was added to mobile app. ZackXBT traced stolen funds through cross-chain swaps to Tron wallets. Recovery is unlikely after XRP was funneled through OTC and swap tools. A U.S. investor has claimed he lost over [...] The post XRP Theft Claims Spark Online Investigation and Wallet Security Questions appeared first on CoinCentral.

XRP Theft Claims Spark Online Investigation and Wallet Security Questions

2025/10/20 18:19
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

TLDR

  • $3M in XRP stolen after investor imported seed into Ellipal mobile app.
  • Ellipal confirmed wallet became hot once seed was added to mobile app.
  • ZackXBT traced stolen funds through cross-chain swaps to Tron wallets.
  • Recovery is unlikely after XRP was funneled through OTC and swap tools.

A U.S. investor has claimed he lost over $3 million worth of XRP in a recent crypto theft. The wallet maker, Ellipal, responded by saying the investor had unknowingly made his cold wallet vulnerable. The case has led to online tracking of the funds and warnings for other crypto holders about wallet safety.

Investor Says Wallet Was Emptied Without Warning

The investor, Brandon, a 54-year-old retiree from North Carolina, said he discovered the loss on October 15. He noticed his XRP balance was missing when checking the Ellipal app on his phone. He later traced the theft to October 12, when a large transaction moved over 1.2 million XRP out of his wallet.

He said he had stored most of his retirement savings in XRP, with plans to buy a house in Las Vegas. Two small 10-XRP test transactions were followed by a large transfer to a new wallet. Brandon said smaller amounts of other tokens, including $1,000 in XLM and $900 in FLR, were not taken.

He posted videos online to explain what happened and also said he filed a report with the FBI’s Internet Crime Complaint Center. He said he also contacted local police but had difficulty reaching cybercrime experts in time.

Ellipal Says Seed Import Turned Cold Wallet Into Hot Wallet

Ellipal released a statement on October 18 saying the issue happened because the wallet’s seed phrase was imported into the Ellipal app. The company said that importing a seed phrase into any device with internet access makes the wallet hot, which weakens its security.

In a message to the user, Ellipal explained that cold wallets remain offline and secure, but once a seed is added to a phone or tablet, it becomes hot. This means private keys are stored on that device and can be accessed if the device is compromised.

Brandon said he used the Ellipal app on both an iPhone and an iPad. He noted that the iPhone app had a blue background, and the iPad app had an orange one. Ellipal told him that blue signals a cold wallet connection while orange means a hot wallet.

The company also stated that it has not seen any thefts linked to its actual hardware devices. It believes this incident resulted from the seed import, not a flaw in its hardware.

Online Analyst Tracks Funds Across Multiple Blockchains

Crypto analyst ZackXBT shared an update on October 19, saying he traced the stolen XRP using on-chain data. He matched the transaction times and amounts to Brandon’s videos. He said the stolen XRP was quickly converted to other assets using a swap tool known as Bridgers, previously called SWFT.

According to ZackXBT, the attacker used over 120 Ripple-to-Tron swaps and then moved the funds to a Tron wallet. He said the tokens were then sent to over-the-counter brokers connected to Huione, a Southeast Asian marketplace under U.S. investigation.

He warned that once funds go through such swaps and OTC routes, recovery becomes very difficult. He also said most crypto recovery firms are not trustworthy and charge high fees for limited help.

Caution Urged for Wallet Users Handling Large Crypto Holdings

ZackXBT said fast action is key in such cases. Reporting the theft to exchanges and law enforcement early can sometimes help freeze assets. However, when funds are moved across chains and swapped fast, stopping the flow becomes nearly impossible.

Brandon said he shared his experience to warn others. He admitted that the loss wiped out nearly all of the couple’s retirement funds. Experts now stress that users should never import a cold wallet’s seed into a hot wallet. They also advise using separate wallets for online and offline storage.

The post XRP Theft Claims Spark Online Investigation and Wallet Security Questions appeared first on CoinCentral.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Coinbase Slams ‘Patchwork’ State Crypto Laws, Calls for Federal Preemption

Coinbase Slams ‘Patchwork’ State Crypto Laws, Calls for Federal Preemption

The post Coinbase Slams ‘Patchwork’ State Crypto Laws, Calls for Federal Preemption appeared on BitcoinEthereumNews.com. In brief Coinbase has filed a letter with the DOJ urging federal preemption of state crypto laws, citing Oregon’s securities suit, New York’s ETH stance, and staking bans. Chief Legal Officer Paul Grewal called state actions “government run amok,” warning that patchwork enforcement “slows innovation and harms consumers.” A legal expert told Decrypt that states risk violating interstate commerce rules and due process, and DOJ support for preemption may mark a potential turning point. Coinbase has gone on the offensive against state regulators, petitioning the Department of Justice that a patchwork of lawsuits and licensing schemes is tearing America’s crypto market apart. “When Oregon can sue us for services that are legal under federal law, something’s broken,” Chief Legal Officer Paul Grewal tweeted on Tuesday. “This isn’t federalism—this is government run amok.” When Oregon can sue us for services that are legal under federal law, something’s broken. This isn’t federalism–this is government run amok. We just sent a letter to @TheJusticeDept urging federal action on crypto market structure to remedy this. 1/3 — paulgrewal.eth (@iampaulgrewal) September 16, 2025 Coinbase’s filing says that states are “expansively interpreting their securities laws in ways that undermine federal law” and violate the dormant Commerce Clause by projecting regulatory preferences beyond state borders. “The current patchwork of state laws isn’t just inefficient – it slows innovation and harms consumers” and demands “federal action on crypto market structure,” Grewal said.  States vs. Coinbase It pointed to Oregon’s securities lawsuit against the exchange, New York’s bid to classify Ethereum as a security, and cease-and-desist orders on staking as proof that rogue states are trying to resurrect the SEC’s discredited “regulation by enforcement” playbook. Oregon Attorney General Dan Rayfield sued Coinbase in April for promoting unregistered securities, and in July asked a federal judge to return the…
Share
BitcoinEthereumNews2025/09/18 11:52
RCO Finance Review: AI Robo Advisor, Fees, Risks & Is It Worth It?

RCO Finance Review: AI Robo Advisor, Fees, Risks & Is It Worth It?

When you first hear about RCO Finance, it sounds like the future: an AI‑powered robo advisor that automatically manages investments across crypto and traditional
Share
Fintechzoom2026/03/12 15:13
SlowMist Introduces Security Framework for Autonomous AI Agents in Crypto

SlowMist Introduces Security Framework for Autonomous AI Agents in Crypto

The post SlowMist Introduces Security Framework for Autonomous AI Agents in Crypto appeared on BitcoinEthereumNews.com. Cybersecurity company SlowMist has introduced
Share
BitcoinEthereumNews2026/03/12 14:59