← Xaman Wallet Impersonation / XRP Airdrop Phishing (2026)1 decision on this page
Audit log
Every state-changing event for Xaman Wallet Impersonation / XRP Airdrop Phishing (2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions carry three independent witnesses — the original source, an Internet Archive snapshot taken at submission time, and a Solana memo signed by our publicly-disclosed publisher key.
- #1publishby system:backfill2026-06-02 20:27:26ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 423,881,809
- sig
3Aa6D69824Kd…vEvNmm4Wexplorer ↗- hash
BbtBVpp1S74W…v8M97wEYsha256 → base58
verifying row…full verify ↗canonical bytes (22759 B) ▸
{"actor":"system:backfill","investigation_id":"e55e573a-171e-4016-a9e6-a24a1466b4e0","kind":"publish","page_slug":"xaman-wallet-impersonation-xrp-airdrop-phishing-2026","published_at":"2026-06-02T20:27:26.574Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Xaman Wallet Impersonation / XRP Airdrop Phishing (2026)","sections":[{"content":"A large-scale, ongoing phishing campaign targeting users of Xaman Wallet (formerly XUMM) — the primary self-custody wallet for the XRP Ledger, built by Netherlands-based XRPL Labs — has been documented across multiple credible outlets in 2026. The campaign involves bad actors creating fake X (Twitter) social media profiles, counterfeit websites, fraudulent browser extensions, and fake desktop wallet downloads, all branded to impersonate the legitimate Xaman product. Wietse Wind, the founder of Xaman and XRPL Labs, confirmed on May 23, 2026 that the volume of impersonation infrastructure being created had reached more than 20 fake X accounts and more than 10 fake domains per day. Wind issued a public warning stating: 'THERE IS NO DESKTOP WALLET! NO AIRDROP! STAY VIGILANT!' The Xaman team is actively reporting fraudulent accounts and domains to platform operators, but reported that new fake accounts and domains continue to emerge faster than they can be removed. XRPL Labs and Xaman are the impersonated parties; they are not implicated in any wrongdoing.","heading":"Overview of the Impersonation Campaign","severity":"critical","sources":[{"credibility":2,"name":"Xaman Founder Warns XRP Holders of Fake Wallets and Airdrop Scams","type":"news_article","url":"https://coinalertnews.com/news/2026/05/25/xrp-scam-warning-xaman"},{"credibility":2,"name":"XRP users warned as fake Xaman airdrop scams spread","type":"news_article","url":"https://crypto.news/xrp-users-warned-as-fake-xaman-airdrop-scams-spread/"},{"credibility":2,"name":"Wietse Wind Warns XRP Holders — Fake Wallets and Airdrops Spreading","type":"news_article","url":"https://coinfomania.com/wietse-wind-warns-xrp-holders-fake-wallets-and-airdrops-spreading/"}]},{"content":"The campaign employs at least five distinct attack vectors, each exploiting Xaman's brand recognition among the XRP retail user base.\n\n1. Fake social media accounts: Scammers create accounts on X (Twitter), Instagram, and Telegram impersonating Xaman, XRPL Labs, and associated executives. These accounts post links to phishing sites, reply to users seeking support, and send unsolicited direct messages. Wietse Wind confirmed more than 20 such accounts appear on X alone each day as of May 2026.\n\n2. Counterfeit domains: Fake websites closely mirroring xaman.app are registered daily. Documented examples include xamansecure[.]online, xamanwallet-token[.]pro, and xaman-wallet[.]com. These sites deploy crypto-drainer tooling: when a visitor connects their wallet, the site triggers an automated transaction that drains the connected wallet's balance. These transactions are irreversible on-chain.\n\n3. Fake browser extensions: At least one fraudulent Chrome browser extension claiming to be a Xaman web wallet was identified in early 2026. Xaman's official product is mobile-only and QR-based; there is no legitimate Xaman browser plugin. The fake extensions request unusual wallet permissions and exfiltrate seed phrases or signing keys.\n\n4. Fake desktop wallet applications: No official Xaman desktop wallet exists. Scam campaigns nonetheless promote downloadable Windows or macOS applications branded as Xaman. These applications are credential-harvesting malware.\n\n5. Unsolicited NFT drops: Separately documented in early 2026, scammers sent unsolicited NFTs to random XRP Ledger addresses. The NFTs contained links or metadata directing recipients to malicious sites, exploiting XRPL's low transaction fees to reach a large number of wallets cheaply.","heading":"Attack Vectors","severity":"critical","sources":[{"credibility":2,"name":"Fake Xaman Website Scam — Removal and recovery steps (PCRisk)","type":"research","url":"https://www.pcrisk.com/removal-guides/34357-fake-xaman-website-scam"},{"credibility":2,"name":"Xaman Monthly $XRP Release Scam — Removal and recovery steps (PCRisk)","type":"research","url":"https://www.pcrisk.com/removal-guides/35283-xaman-monthly-xrp-release-scam"},{"credibility":2,"name":"Xaman Founder Warns XRP Users: There Is No Xaman Browser Plugin as Fake Extensions Emerge","type":"news_article","url":"https://thecryptobasic.com/2026/03/05/xaman-founder-warns-xrp-users-there-is-no-xaman-browser-plugin-as-fake-extensions-emerge/"},{"credibility":2,"name":"XRP Wallets Under Attack as Fake Xaman NFT Scam Spreads Fast (MEXC News)","type":"news_article","url":"https://www.mexc.com/news/827281"}]},{"content":"Concurrent with the Xaman-specific impersonation wave, a broader XRP airdrop fraud campaign operated in May 2026. David Schwartz, the former Chief Technology Officer of Ripple and one of the original architects of the XRP Ledger, issued a public warning on approximately May 14, 2026, stating: 'SCAM ALERT: There has been a huge escalation lately in airdrop and giveaway scams targetting XRPL users lately. Any such posts you see are likely scams. Anyone claiming to be me on Instagram, Telegram, or almost anywhere else is likely a scammer. Stay safe XRP fam.' Schwartz noted that fake accounts impersonating him had appeared on Instagram and Telegram. These XRP airdrop and fake staking campaigns direct users to counterfeit Ripple-branded sites and request wallet connections or seed phrase entry. Ripple has never conducted a public XRP airdrop; any communication claiming otherwise is fraudulent.","heading":"Parallel XRP Airdrop and Ripple Impersonation Campaign","severity":"high","sources":[{"credibility":2,"name":"Ripple insider warns XRP holders as fake airdrop scams surge across XRPL (CryptoSlate)","type":"news_article","url":"https://cryptoslate.com/ripple-insider-warns-xrp-holders-as-fake-airdrop-scams-surge-across-xrpl/"},{"credibility":2,"name":"Ripple CTO David Schwartz warns of XRPL airdrop scams and wallet drainers (BingX News, May 14, 2026)","type":"news_article","url":"https://bingx.com/en/news/post/ripple-cto-david-schwartz-warns-of-xrpl-airdrop-scams-and-wallet-drainers-may"},{"credibility":2,"name":"Ripple News: CTO Issues Urgent XRP USD Scam Warning (99Bitcoins / Yahoo Finance)","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/ripple-news-cto-issues-urgent-111552638.html"}]},{"content":"At least one victim loss has been publicly reported. A community member identified as 'Bigdealee' on social media reported losing approximately $400,000 worth of XRP as a result of a Xaman impersonation scam, according to Coin Edition's May 26, 2026 reporting. This figure is sourced from a community post and has not been independently verified through court records or on-chain analysis; it should be treated as a plausible but unverified individual report. Because XRP Ledger transactions are irreversible once confirmed on-chain, victims of wallet-draining attacks have no technical mechanism to recover stolen funds. The combination of high daily fake-account creation volume (20+ per day on X alone), the large retail user base of Xaman (reported to have over 538 million XRP active on the platform in early 2026), and irreversible transaction finality creates systemic exposure for non-technical users.","heading":"Victim Losses and Scale","severity":"high","sources":[{"credibility":2,"name":"XRP Community Hit With Warning Amid Fresh Xaman User Scam Wave (Coin Edition, May 26, 2026)","type":"news_article","url":"https://coinedition.com/xrp-community-hit-with-warning-amid-fresh-xaman-user-scam-wave/"},{"credibility":2,"name":"Xaman Founder Warns XRP Users: There Is No Xaman Browser Plugin as Fake Extensions Emerge (The Crypto Basic, March 5, 2026)","type":"news_article","url":"https://thecryptobasic.com/2026/03/05/xaman-founder-warns-xrp-users-there-is-no-xaman-browser-plugin-as-fake-extensions-emerge/"}]},{"content":"Security research firm PCRisk documented multiple fraudulent domains impersonating Xaman in 2026. The domain xamansecure[.]online was identified as a credential-harvesting phishing site designed as 'an almost perfect imitation of xaman.app.' PCRisk's website scanner classified it as Malicious (CRDF) and Phishing (SOCRadar). The site's IP was recorded as 199.188.205.227. The domains xamanwallet-token[.]pro and xaman-wallet[.]com were separately documented hosting 'monthly XRP release' lure pages, which deploy crypto-drainer tooling upon wallet connection. These drainer tools are capable of initiating and executing fund-transfer transactions autonomously once a victim approves a wallet connection, with no further interaction required from the victim. PCRisk's documentation does not include specific blockchain addresses associated with the attacker wallets.","heading":"Technical Infrastructure of Fake Sites","severity":"high","sources":[{"credibility":2,"name":"Fake Xaman Website Scam — Removal and recovery steps (PCRisk)","type":"research","url":"https://www.pcrisk.com/removal-guides/34357-fake-xaman-website-scam"},{"credibility":2,"name":"Xaman Monthly $XRP Release Scam — Removal and recovery steps (PCRisk)","type":"research","url":"https://www.pcrisk.com/removal-guides/35283-xaman-monthly-xrp-release-scam"}]},{"content":"XRPL Labs and the Xaman team have responded to the campaign through repeated public warnings, in-wallet alert filters, and active reporting of fraudulent accounts and domains to platform operators. The team's official Help Center explicitly documents that the Xaman Support xApp within the mobile application is 'the only 100% trustworthy way to reach' the team, and that users should not respond to any direct messages on X, Telegram, or other social platforms claiming to be Xaman support. The official Xaman X accounts are @XamanWallet, @XamanHelp, and @XRPLLabs. The team has confirmed that Xaman has no browser plugin, no desktop wallet, and no official Telegram channel. The official app is available exclusively through the Apple App Store and Google Play Store. Wietse Wind noted that fighting the campaign consumed entire weekends of staff time. The Xaman team also added in-wallet warning banners and filters to alert users encountering suspicious transactions.","heading":"Official Response from Xaman / XRPL Labs","severity":"medium","sources":[{"credibility":1,"name":"Official communication channels — Xaman Help Center","type":"official","url":"https://help.xaman.app/app/learning-more-about-xaman/official-communication-channels"},{"credibility":2,"name":"Wietse Wind Warns XRP Holders — Fake Wallets and Airdrops Spreading (Coinfomania, May 25, 2026)","type":"news_article","url":"https://coinfomania.com/wietse-wind-warns-xrp-holders-fake-wallets-and-airdrops-spreading/"},{"credibility":2,"name":"Xaman Wallet Founder Warns of Coordinated Scam Targeting XRPL Users (KuCoin News)","type":"news_article","url":"https://www.kucoin.com/news/flash/xaman-wallet-founder-warns-of-coordinated-scam-targeting-xrpl-users"}]},{"content":"Several structural factors make the Xaman user base an attractive target for social-engineering phishing campaigns. First, Xaman is the dominant retail wallet interface for the XRP Ledger, with over 538 million XRP reported active on the platform in early 2026. Its brand is closely associated with XRP for many non-technical retail holders who may not distinguish between the wallet app and the underlying ledger. Second, XRP's price appreciation in 2025-2026 (rising from $1.84 to as high as $2.41 in early 2026) attracted a new wave of retail investors less familiar with self-custody security practices. Third, XRP spot ETF inflows reached $25.8 million on a single day in May 2026 and cumulative inflows of $1.36 billion, indicating growing institutional and retail interest that scammers exploit. Fourth, XRPL's low transaction fees make it economically viable for scammers to distribute unsolicited NFTs and spam wallet addresses at scale. Fifth, industry-wide context shows crypto scams totaled approximately $1.37 billion in 2025, a 64% increase from 2024, with centralized and non-technical user platforms accounting for a growing share of losses.","heading":"Why the XRP / Xaman User Base Is Particularly Targeted","severity":"medium","sources":[{"credibility":2,"name":"Ripple insider warns XRP holders as fake airdrop scams surge across XRPL (CryptoSlate, May 14, 2026)","type":"news_article","url":"https://cryptoslate.com/ripple-insider-warns-xrp-holders-as-fake-airdrop-scams-surge-across-xrpl/"},{"credibility":2,"name":"Xaman Founder Warns XRP Users: There Is No Xaman Browser Plugin as Fake Extensions Emerge (The Crypto Basic)","type":"news_article","url":"https://thecryptobasic.com/2026/03/05/xaman-founder-warns-xrp-users-there-is-no-xaman-browser-plugin-as-fake-extensions-emerge/"},{"credibility":2,"name":"Wallet Founder Warns of Coordinated Scam Targeting XRPL Users (KuCoin / Cryptonews.net, February 2026)","type":"news_article","url":"https://cryptonews.net/news/security/32442888/"}]},{"content":"Based on official documentation from XRPL Labs, users can identify genuine Xaman resources as follows. The official website and wallet download portal is xaman.app. The only legitimate mobile applications are distributed via the Apple App Store (app ID 1492302343) and Google Play Store. Official X accounts are @XamanWallet, @XamanHelp, and @XRPLLabs. The official blog is at blog.xaman.app. Xaman has no browser extension, no desktop wallet application, no Telegram channel, and no WhatsApp presence. The company does not initiate unsolicited direct messages or emails. In-app support is accessed exclusively through the Xaman Support xApp within the mobile application. Any account, website, or application claiming to be Xaman outside these channels should be treated as fraudulent.","heading":"How to Identify Legitimate Xaman Resources","severity":"low","sources":[{"credibility":1,"name":"Official communication channels — Xaman Help Center","type":"official","url":"https://help.xaman.app/app/learning-more-about-xaman/official-communication-channels"},{"credibility":1,"name":"Xaman — The Best XRP Wallet for Security and Control (official site)","type":"official","url":"https://xaman.app/"}]}],"sources_used":[{"credibility":2,"name":"Xaman Founder Warns XRP Holders of Fake Wallets and Airdrop Scams (CoinAlert News, May 25, 2026)","type":"news_article","url":"https://coinalertnews.com/news/2026/05/25/xrp-scam-warning-xaman"},{"credibility":2,"name":"XRP users warned as fake Xaman airdrop scams spread (Crypto.news, May 24, 2026)","type":"news_article","url":"https://crypto.news/xrp-users-warned-as-fake-xaman-airdrop-scams-spread/"},{"credibility":2,"name":"Xaman Founder Warns XRP Users: There Is No Xaman Browser Plugin as Fake Extensions Emerge (The Crypto Basic, March 5, 2026)","type":"news_article","url":"https://thecryptobasic.com/2026/03/05/xaman-founder-warns-xrp-users-there-is-no-xaman-browser-plugin-as-fake-extensions-emerge/"},{"credibility":2,"name":"XRP Community Hit With Warning Amid Fresh Xaman User Scam Wave (Coin Edition, May 26, 2026)","type":"news_article","url":"https://coinedition.com/xrp-community-hit-with-warning-amid-fresh-xaman-user-scam-wave/"},{"credibility":2,"name":"Xaman Wallet Founder Warns of Coordinated Scam Targeting XRPL Users (KuCoin News)","type":"news_article","url":"https://www.kucoin.com/news/flash/xaman-wallet-founder-warns-of-coordinated-scam-targeting-xrpl-users"},{"credibility":2,"name":"Fake Xaman Website Scam — Removal and recovery steps (PCRisk)","type":"research","url":"https://www.pcrisk.com/removal-guides/34357-fake-xaman-website-scam"},{"credibility":2,"name":"Xaman Monthly $XRP Release Scam — Removal and recovery steps (PCRisk)","type":"research","url":"https://www.pcrisk.com/removal-guides/35283-xaman-monthly-xrp-release-scam"},{"credibility":2,"name":"Wietse Wind Warns XRP Holders — Fake Wallets and Airdrops Spreading (Coinfomania, May 25, 2026)","type":"news_article","url":"https://coinfomania.com/wietse-wind-warns-xrp-holders-fake-wallets-and-airdrops-spreading/"},{"credibility":2,"name":"Ripple insider warns XRP holders as fake airdrop scams surge across XRPL (CryptoSlate, May 14, 2026)","type":"news_article","url":"https://cryptoslate.com/ripple-insider-warns-xrp-holders-as-fake-airdrop-scams-surge-across-xrpl/"},{"credibility":2,"name":"Ripple CTO David Schwartz warns of XRPL airdrop scams and wallet drainers (BingX News, May 14, 2026)","type":"news_article","url":"https://bingx.com/en/news/post/ripple-cto-david-schwartz-warns-of-xrpl-airdrop-scams-and-wallet-drainers-may"},{"credibility":2,"name":"Ripple News: CTO Issues Urgent XRP USD Scam Warning (99Bitcoins / Yahoo Finance)","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/ripple-news-cto-issues-urgent-111552638.html"},{"credibility":2,"name":"XRP Wallets Under Attack as Fake Xaman NFT Scam Spreads Fast (MEXC News, March 2026)","type":"news_article","url":"https://www.mexc.com/news/827281"},{"credibility":2,"name":"No Airdrop: XRPL Developer Repeats Crucial Warning to XRP Community (U.Today)","type":"news_article","url":"https://u.today/no-airdrop-xrpl-developer-repeats-crucial-warning-to-xrp-community"},{"credibility":2,"name":"Wallet Founder Warns of Coordinated Scam Targeting XRPL Users (Cryptonews.net, February 2026)","type":"news_article","url":"https://cryptonews.net/news/security/32442888/"},{"credibility":1,"name":"Official communication channels — Xaman Help Center (official)","type":"official","url":"https://help.xaman.app/app/learning-more-about-xaman/official-communication-channels"},{"credibility":1,"name":"Xaman — The Best XRP Wallet for Security and Control (official site)","type":"official","url":"https://xaman.app/"},{"credibility":2,"name":"XRPL Wallet Xumm Rebrands as Xaman With Multi-Network Support Involving Xahau (The Crypto Basic, December 2023)","type":"news_article","url":"https://thecryptobasic.com/2023/12/18/xrpl-wallet-xumm-rebrands-as-xaman-with-multi-network-support-involving-xahau/"},{"credibility":1,"name":"XRPL Labs GitHub organization","type":"official","url":"https://github.com/XRPL-Labs"},{"credibility":2,"name":"XRPL Labs Founder Sends Critical Warning to XRP Holders (Times Tabloid, August 2025)","type":"news_article","url":"https://timestabloid.com/xrpl-labs-founder-sends-critical-warning-to-xrp-holders/"},{"credibility":2,"name":"No Airdrop: XRPL Developer Repeats Crucial Warning (Cryptonews.net)","type":"news_article","url":"https://cryptonews.net/news/security/32911570/"}],"summary":"Beginning at least as early as March 2026 and escalating sharply through May 2026, a sustained and coordinated phishing campaign has impersonated Xaman Wallet — the dominant self-custody wallet for the XRP Ledger, developed by XRPL Labs — across fake social media accounts, counterfeit domains, fraudulent browser extensions, and fake desktop wallet applications. Xaman founder Wietse Wind confirmed on May 23, 2026 that more than 20 fake X/Twitter accounts and more than 10 fraudulent domains are created daily as part of this campaign. The legitimate Xaman product and XRPL Labs are the impersonated party and bear no responsibility for the fraudulent activity.","timeline":[{"date":"2025-04-01","event":"Wietse Wind issued an earlier warning (approximate date) that impersonation accounts were sending direct messages promoting fake Xaman web wallets and browser extensions, indicating the campaign predates 2026.","source":"The Crypto Basic","source_url":"https://thecryptobasic.com/2026/03/05/xaman-founder-warns-xrp-users-there-is-no-xaman-browser-plugin-as-fake-extensions-emerge/"},{"date":"2025-08-11","event":"Wietse Wind warned publicly: 'Scammers are sending emails about interruptions and Xaman desktop clients. THIS IS FAKE! THIS IS SCAM!' — indicating fake desktop-client phishing emails were circulating by at least August 2025.","source":"Times Tabloid","source_url":"https://timestabloid.com/xrpl-labs-founder-sends-critical-warning-to-xrp-holders/"},{"date":"2026-02-16","event":"Wietse Wind issued a detailed coordinated-scam warning covering fake sign requests, fraudulent NFTs, counterfeit desktop wallets, fake support DMs, and phishing emails, as reported by KuCoin news.","source":"KuCoin News / Cryptonews.net","source_url":"https://cryptonews.net/news/security/32442888/"},{"date":"2026-03-01","event":"Reports published of scammers sending unsolicited NFTs to random XRP Ledger addresses, luring recipients to malicious sites claiming to distribute exclusive Xaman 'beta access pass' NFTs.","source":"MEXC News","source_url":"https://www.mexc.com/news/827281"},{"date":"2026-03-05","event":"Wietse Wind warned XRP users: 'There is NO browser plugin. There is NO desktop wallet.' A fraudulent Chrome extension falsely claiming to be Xaman's web version was identified, requesting unusual wallet permissions.","source":"The Crypto Basic","source_url":"https://thecryptobasic.com/2026/03/05/xaman-founder-warns-xrp-users-there-is-no-xaman-browser-plugin-as-fake-extensions-emerge/"},{"date":"2026-05-14","event":"David Schwartz, Ripple CTO Emeritus, issued a public scam alert: 'SCAM ALERT: There has been a huge escalation lately in airdrop and giveaway scams targetting XRPL users lately.' Schwartz warned that impersonation accounts for him existed on Instagram, Telegram, and other platforms.","source":"CryptoSlate / BingX News","source_url":"https://cryptoslate.com/ripple-insider-warns-xrp-holders-as-fake-airdrop-scams-surge-across-xrpl/"},{"date":"2026-05-23","event":"Wietse Wind posted on X: 'THERE IS NO DESKTOP WALLET! NO AIRDROP! STAY VIGILANT!' Wind confirmed 20+ fake X accounts and 10+ fake domains created daily impersonating Xaman, and disclosed the team spent entire weekends fighting the campaign.","source":"Crypto.news / U.Today / Coinfomania","source_url":"https://crypto.news/xrp-users-warned-as-fake-xaman-airdrop-scams-spread/"},{"date":"2026-05-25","event":"Multiple crypto outlets including CoinAlert News and Coinfomania published amplified coverage of Wind's May 23 warning, reaching broader audiences.","source":"CoinAlert News","source_url":"https://coinalertnews.com/news/2026/05/25/xrp-scam-warning-xaman"},{"date":"2026-05-26","event":"Coin Edition reported a community member ('Bigdealee') claiming to have lost approximately $400,000 in XRP to a Xaman impersonation scam. This is an unverified community report.","source":"Coin Edition","source_url":"https://coinedition.com/xrp-community-hit-with-warning-amid-fresh-xaman-user-scam-wave/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision fe209272-739e-45ba-becd-e876a25b5d02
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.