A user lost $2.1 million in cryptocurrency after clicking on a phishing link from ChatGPT

04.09.2026

One wrong URL and one wallet signature cost a crypto user approximately $2.1 million. According to an on-chain investigation by VAL, the victim followed a link received in a ChatGPT response while looking for a way to swap tokens, connected a wallet, and granted a smart contract unlimited access to the assets. The case is notable not only because of the size of the loss. The attackers did not need to hack the wallet or obtain the seed phrase — the user personally approved the permission that allowed the assets to be withdrawn.

How the attack happened

The user was looking for a way to swap sFLR for WFLR and, according to their account, asked ChatGPT for a recommendation. The response included a link to a website that turned out to be a phishing page. After connecting the wallet, the user signed an unlimited approval — a permission that allows a specific smart contract to spend tokens without a predefined limit. Once the approval was granted, the attacker used the transferFrom function and withdrew around 1.9 million FXRP, valued at approximately $2.1 million at the time.

Why the attacker did not need access to the wallet

Approval phishing works differently from traditional seed phrase theft. The user remains the owner of the wallet and may not notice anything suspicious until the assets are transferred. The key element of the attack is the permission granted to a smart contract. If a user approves an unlimited allowance, the attacker can potentially withdraw the entire available balance of the corresponding token.

The following actions are especially risky:

  • signing an Unlimited / Infinite Approve request on an unfamiliar website;
  • connecting a primary wallet to a service through a link from search results, ads, Telegram, or an AI service;
  • confirming a transaction without checking the contract address and requested permissions;
  • using an unfamiliar DEX or bridge simply because it appeared first in a recommendation.

Where the stolen funds went

On-chain analyst VAL tracked the subsequent movement of the assets through several wallets. Part of the funds was converted from FLR to DAI via OpenOcean, then transferred between addresses and exchanged for ETH. Some of the ETH was later sent through Tornado Cash, making further tracking significantly more difficult. According to the investigation, the infrastructure linked to the attack was not used for a single transaction only. Other transfers also passed through related addresses, while the total volume associated with the phishing scheme was estimated at more than $2.2 million.

The main issue is not ChatGPT itself

The story can easily be reduced to a headline like “ChatGPT caused a $2 million theft,” but technically that would be inaccurate. The loss occurred after the user opened a third-party phishing website and approved a dangerous wallet permission. However, the case highlights a new problem: AI services are becoming another channel through which potentially malicious links can reach users. People often treat an AI-generated answer as a ready-made recommendation and may trust links in such responses more than ordinary search results. For scammers, this creates another attack vector. Previously, the goal was to push phishing pages into Google results, paid ads, and social media. AI assistants are now becoming part of that landscape as well.

Phishing is becoming harder to recognize

Modern crypto attacks do not always begin with an obviously suspicious email or a fake giveaway. A fraudulent website can almost perfectly replicate the interface of a legitimate DEX, bridge, or exchange platform. The most dangerous moment often comes after the wallet is connected: the user sees a familiar MetaMask or other wallet confirmation window and approves the request almost automatically. This is why Web3 security is gradually shifting from the simple rule “never share your seed phrase” to a broader principle — understand exactly what you are signing.

How to reduce the risk

  • verify the domain of a crypto service through several independent sources;
  • do not assume a link is safe simply because it came from an AI tool, search engine, or advertising platform;
  • avoid Unlimited Approve unless the service genuinely requires ongoing access to your tokens;
  • use a separate wallet with a limited balance when interacting with unfamiliar DeFi platforms;
  • regularly review and revoke unnecessary token approvals;
  • for large transactions, first perform a small test transaction.
The main takeaway is simple: an interface can look legitimate and a link can come from a source you trust, but the final authorization still happens inside your wallet. AI can help users find information, but when dealing with cryptocurrency, the website address, smart contract, and requested permissions should always be verified separately — especially when significant funds are involved.
Go back

Protected by

Powered by

Operator “Online”