XRP Holder Loses 400,000 Tokens After Phishing Email Posing as Ledger Update
Key Takeaways
- •The victim reportedly lost roughly 400,000 XRP after interacting with a phishing email disguised as a Ledger update.
- •Attackers used a fake software update link to obtain the information needed to drain the hardware wallet.
- •About 50,000 XRP held in a separate insured custody account remained secure due to callback and voice verification requirements.
- •Kaltekis said the incident shows self-custody can still be vulnerable when users are deceived by sophisticated phishing attempts.
- •Crypto holders are urged to verify unexpected wallet-update requests through official channels rather than email links.

An XRP holder lost 400,000 tokens overnight after responding to a phishing email that appeared to be a routine hardware wallet update, according to an account shared by crypto adviser George Kaltekis.
Late-Night Easter Call
Kaltekis said he received a panicked call at about 10 p.m. on Easter night, after the theft had taken place. He said the timing itself suggested something was wrong, noting that calls at that hour rarely bring good news.
The victim reportedly held roughly 400,000 XRP on a hardware wallet. While spending the holiday with family, he received an email that appeared to come from Ledger and instructed him to update his device. Believing the message was a standard software update request, he clicked through and entered his wallet information.
How the Scam Worked
The phishing email, disguised as a Ledger update, directed the victim to a fake software update link. By following the link and entering the requested information, he unknowingly provided attackers with the credentials needed to drain the wallet. The 400,000 XRP was then stolen.
Hardware wallets are designed to keep private keys offline, but that protection can be bypassed if a user is tricked into revealing recovery information or approving a malicious process outside normal safeguards. For that reason, unexpected wallet-update emails are a common high-risk scenario: legitimate device maintenance should be verified through official channels rather than links sent in unsolicited messages.
Kaltekis said phishing attempts have become increasingly convincing in recent years. He noted that even people who work professionally in cybersecurity have described difficulty distinguishing genuine communications from fraudulent ones.
Separate Custody Account Was Untouched
The loss was not total. The victim still had about 50,000 XRP held in a separate insured custody account. Those funds remained secure because the account required additional verification before any transaction could be approved, including callback confirmation and voice verification before assets could be moved.
That contrast highlights a practical trade-off in crypto storage. Self-custody gives holders direct control over assets, while custody arrangements may add procedural checks that slow or block unauthorized transfers. Neither approach removes all risk, but larger balances often prompt users to think more carefully about how access, verification, and recovery are handled.
Lesson for Self-Custody Users
Kaltekis said the account was not intended to discourage self-custody, which he described himself as strongly supporting. Instead, he said the case shows that self-custody, while valuable, is not automatically protected from sophisticated phishing attempts.
A single mistake made under ordinary circumstances, by someone simply checking email, was enough to produce a major loss. The incident adds to a growing number of similar accounts circulating across the crypto industry and underscores the need for holders of XRP, Bitcoin, and other digital assets to carefully verify unexpected update requests and consider additional safeguards for larger holdings.