Skip to content
Crypto investor lost $2.1 million due to phishing in ChatGPT

Crypto investor lost $2.1 million due to phishing in ChatGPT

Coinspot September 5, 2026

A crypto investor communicating with ChatGPT in Russian lost $2.1 million after clicking a link suggested by the chatbot and connecting their wallet to a phishing site. Blockchain analyst VAL examined the details of the incident.

How the Investor Landed on a Phishing Page

A user with the nickname Alex asked ChatGPT where to exchange the sFLR token for WFLR. The response included a link to a page that the investor believed was a legitimate crypto exchange service.

Alex connected his wallet to the site and confirmed a transaction with so-called unlimited approval. Within seconds, attackers used the transferFrom function and withdrew 1.9 million FXRP from his address. At the time of the theft, this asset was valued at approximately $2.1 million.

Essentially, the user gave permission to withdraw funds himself, mistaking the malicious operation for a routine step in the exchange process. In the crypto sphere, such a mistake can be as dangerous as a mistaken bank transaction: it is almost impossible to reverse after confirmation.

What Was Learned From the Movement of Funds

After the theft, Alex posted transaction data and wallet addresses that could be linked to the theft on social network X. He asked other users to help track the path of the stolen funds.

VAL noticed a transfer of 50 Ethereum to Tornado Cash from a wallet that had previously received 120,000 DAI. Funds from other users also came to the same address. The balance still had 380,000 DAI, and 310,000 DAI had already been distributed between two other wallets.

Further checks showed that 700,000 DAI had been sent to this address two months before the incident—in a total of 13 transactions. Before sending, users exchanged FLR for DAI via OpenOcean, then transferred the funds further.

The Wallet Was Active for Several Months

According to VAL, the suspicious wallet had been operating since at least April. It received various amounts of FLR: some funds were sent to other addresses, some were transferred to other networks. Later, the assets were converted to DAI and then to Ethereum.

A total of 889 Ethereum was sent to one of the linked wallets. According to the investigation, these funds are still at the same address.

VAL also checked whether the phishing link still appears in ChatGPT responses. According to him, after the incident, it no longer appears. After the $2.1 million theft, the wallet stopped receiving FLR from outside, but the movement of already stolen funds continued.

Why Such Attacks Are Dangerous for Crypto Investors

This case shows that even an experienced crypto investor can lose funds if they trust a link without additional verification. In the crypto market, not only investments and liquidity are important, but also basic authentication of sites, contract addresses, and wallet permissions.

Before exchanging tokens, users usually verify information in several places:

On the project website

In a blockchain explorer

Through major platforms, such as Binance

But neither Bitcoin nor other crypto assets protect the owner from error if they themselves sign a dangerous approval.

A similar scheme previously affected Hyperliquid clients. In August, they lost $550,000 after clicking fake ads on Google that led to a phishing site.

{ “@context”: “ “@type”: “Article”, “ ”: [ { “@type”: “Thing”, “name”: “Bitcoin” }, { “@type”: “Thing”, “name”: “cryptocurrency” }, { “@type”: “Thing”, “name”: “blockchain” }, { “@type”: “Product”, “name”: “Ethereum” }, { “@type”: “Organization”, “name”: “Binance” }, { “@type”: “Thing”, “name”: “authentication” }, { “@type”: “Organization”, “name”: “CoinMarketCap” } ] }

News digital currencies, fintech trends and financial innovations

CoinSpot.io - the largest Runet resource digital currencies, fintech trends and financial innovations. We talk technologies, startups and entrepreneurs shaping the face of the financial world. Venture investments, p2p and digital technologies, cryptocurrencies, analytics and reviews - everything you need to know to stay in trend and earn.

Full or partial use of site materials is allowed only with the written permission of the editorial office, and a link to the source is mandatory!

Extracted Entities

Attack Types (1)

Companies (1)

Domains (1)

Platforms (2)

Tools (1)