Back to Blog
Web3 Security

Fake Flare Network Staking Site Drains $8.5M in XRP, Two Arrested

A cloned staking site, a fabricated Wikipedia entry, and a paid actor were enough to convince 71 investors to hand over 3.4 million XRP — a reminder that brand impersonation, not smart-contract exploits, remains crypto's most reliable attack surface.

PyramidLedger Research4 min read
Share

Key Takeaways

  • A site at **fxrpntwork.com** impersonated Flare Network's FXRP product for just eight days (16–23 October 2025) and still took 3.4 million XRP (~$8.5M) from 71 investors.
  • The operation's most effective tool wasn't code — it was fabricated Wikipedia entries, Naver blog posts, and a paid actor filming fake review videos.
  • Seoul police have detained two men on aggravated fraud charges and traced roughly $18.8M through wallets and exchange accounts; a third suspect is subject to an Interpol Red Notice.
  • The tell was in the pitch, not the platform: guaranteed 1.5–1.8% monthly returns with protected principal is not a real staking product.

South Korean police say a fake staking platform impersonating Flare Network took roughly 3.4 million XRP — about $8.5 million at the time, with the traceable total closer to $18.8M — from 71 investors in a scheme that ran for just eight days. Two men have been detained on aggravated fraud charges; a third is wanted on an Interpol Red Notice. There is no indication Flare Network's actual infrastructure, smart contracts, or FXRP token were compromised — this was a pure impersonation play.

How the site pulled it off

The scam site, registered at fxrpntwork.com, was live from 16 to 23 October 2025 and marketed itself as an official Flare/FXRP staking product offering guaranteed principal protection plus monthly returns of 1.5% to 1.8%. According to reporting from Decrypt, the operators didn't rely on a single ad campaign — they built an ecosystem of fake legitimacy:

  • Fabricated Wikipedia entries describing the platform as genuine
  • Naver blog and Tistory posts written to look like organic Korean-language coverage
  • Planted online news articles
  • YouTube videos, including at least one featuring a paid actor posing as a satisfied user

That layering is what let the site pass a casual credibility check: a prospective investor searching the platform's name would find a Wikipedia-style summary, a blog review, and a video testimonial — all fabricated, all pointing the same direction. After eight days and 71 deposits, the operators disappeared with the funds.

The guaranteed-return pitch was the real red flag

No legitimate staking product — on Flare or any other network — can guarantee a fixed monthly yield with protected principal. Staking rewards float with network participation, validator performance, and token economics; they cannot be underwritten as a flat rate. A pitch that promises otherwise is describing a payout structure, not a protocol. That single claim was the most reliable signal in the entire operation, and it was verifiable without any technical due diligence at all.

Why this pattern keeps working

Per CoinDesk, Seoul police executed 54 search and seizure warrants and froze 17.3 billion won (roughly $12M) in assets across overseas exchanges after an exchange's fraud-monitoring team flagged unusual deposit patterns tied to the case — the tip that opened the investigation in the first place. That detail matters: the eventual disruption came from exchange-side transaction monitoring, not from the victims' own diligence, and by then most of the money had already moved through wallets and offshore accounts. For organisations whose brand can be cloned this cheaply — a domain, a Wikipedia stub, a rented actor — the defensible move is proactive: monitoring for impersonating domains and fake "official" listings before they accumulate the secondary content (reviews, wiki pages, videos) that makes them look real. Once that ecosystem exists, victims judge the platform on social proof rather than on the protocol itself, and the fraud outruns any after-the-fact takedown.

Frequently Asked Questions

Was Flare Network itself hacked?

No. Reporting indicates this was a brand-impersonation scam — a lookalike site (fxrpntwork.com) claiming to offer official Flare/FXRP staking. There's no evidence Flare Network's protocol, contracts, or token were compromised.

What made the scam convincing?

Layered fake legitimacy: a fabricated Wikipedia entry, Naver blog posts, planted news articles, and YouTube videos featuring a paid actor, all pointing to the same fake platform — enough to pass a casual credibility check.

How can investors spot a fake staking site?

Treat any guaranteed fixed monthly return with "protected principal" as disqualifying — real staking yields float. Verify the domain directly against the project's official channels rather than trusting search results, reviews, or third-party summaries.

Sources

  1. 1Two arrested after Flare Network staking site scammed users out of 3.4 million XRP (~$8.5 million)Web3 Is Going Great
  2. 2Fake Flare Network Staking Site Drained $8.5M in XRP: Seoul PoliceDecrypt
  3. 3Scammers stole millions of XRP tokens from dozens of investors via a fake Flare Network siteCoinDesk
Share

Read next