$3 Million in XRP Disappears: A Retiree’s Shocking Tale of Theft and User Error
In a shocking turn of events, an American retiree, Brandon, has reported that more than $3 million worth of XRP disappeared from his account, sending ripples of concern through the cryptocurrency community. The incident unfolded after he checked the Ellipal mobile app on October 15, discovering that his balance had vanished. This startling discovery ignited an on-chain tracing effort led by the pseudonymous analyst ZackXBT, shedding light on the ramifications of poor security practices in cryptocurrency storage.
The Victim’s Account: A Retirement Fund in Peril
Brandon, a 54-year-old from North Carolina, shared that he had invested in XRP since 2017. Having accumulated a substantial amount over the years, this cryptocurrency formed the bulk of his and his wife’s retirement savings, with plans to purchase a house in Las Vegas. In a series of YouTube videos since October 15, he described how he uncovered the theft by checking the Ellipal app on a Wednesday. After some digging, he deduced that the theft had occurred a few days prior, on Sunday, October 12.
He noted that he initially saw two small withdrawals of 10 XRP each, which were test transactions. Then, a staggering amount—approximately 1,209,990 XRP—was swiftly drained to a newly created address, followed by the rapid distribution across dozens of wallets. Despite the theft, he reported that smaller balances of other assets like XLM and FLR remained untouched.
Authorities Called In: Filing for Help
In light of this distressing situation, Brandon promptly filed a report with the FBI’s Internet Crime Complaint Center and reached out to local authorities. However, he expressed frustration over the lack of quick responses from specialized cyber units, leaving him in a state of uncertainty regarding the fate of his funds. He remains perplexed about how the theft occurred from what he believed to be a secure setup.
Ellipal’s Response: Cold Wallet vs. Hot Wallet Confusion
Ellipal, the hardware wallet provider, responded publicly on October 18, elaborating that Brandon had mistakenly imported his hardware wallet’s seed phrase into the Ellipal mobile app. This action essentially transformed his cold wallet into a hot wallet, significantly compromising its security.
In an email to Brandon, Ellipal explained that using the seed on a mobile device led to the seed and the resulting private keys being stored on that device, thus exposing them to potential theft. Brandon mentioned he had the Ellipal app on both an iPhone and an iPad, noting differences in backgrounds: blue for a cold wallet connection on his iPhone and orange indicating a hot wallet on his iPad.
Ellipal was keen to clarify that their hardware devices are designed to be air-gapped, asserting that they have not witnessed thefts stemming from the hardware itself. Their narrative places the onus of the theft squarely on user error, although this does not conclusively illustrate how the theft transpired.
ZackXBT’s Investigation: Tracing the Stolen Funds
Following up on the story, ZackXBT released an investigation on October 19, identifying the address where the stolen XRP was sent. By analyzing the timing and amounts associated with the transactions, he reported that the attacker executed over 120 Ripple-to-Tron swaps using the service formerly known as SWFT. Interestingly, some block explorers link these transactions to “Binance” due to liquidity operations that involve the exchange.
ZackXBT tracked the funds as they consolidated onto a Tron wallet and were subsequently funneled into over-the-counter (OTC) brokers, particularly those in Southeast Asia. This OTC marketplace has attracted scrutiny from U.S. authorities in the past, raising further red flags about the potential for recovering lost funds.
Recovery Realities and User Lessons
ZackXBT advised caution regarding recovery attempts, stating that many “recovery” firms often engage in predatory practices, charging high fees for little more than superficial reports. He stressed the importance of reporting to credible investigators quickly, as prompt actions can help flag or freeze the stolen funds. However, once cryptocurrency flows through cross-chain swaps and OTC venues, recovery chances become increasingly slim.
Brandon’s unfortunate tale serves as a critical reminder for cryptocurrency users: if your primary goal is cold storage, never type your hardware wallet’s seed phrase into any mobile or desktop app. Instead, it’s advisable to use a distinct seed for any hot wallet and implement a BIP39 passphrase for enhanced security.
Despite the emotional toll of losing what he viewed as his retirement plan, Brandon shared his experience not just as a cautionary tale but as a call for guidance from the community. His hope is to prevent others from suffering a similar fate, even while grappling with the realization that recovery might be an uphill battle.

