Close Menu
21stNews21stNews

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Morocco and Seven African Countries to March at 2026 Winter Olympics Opening Ceremony

    February 6, 2026

    Amazon Q4 Sales Hit $213.4 Billion as AWS Growth Accelerates

    February 6, 2026

    Evacuations Continue in Larache, Nearby Provinces, Over 150,000 Relocated Evacuations Continue in Larache, Nearby Provinces, Over 150,000 Relocated

    February 6, 2026
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    Pinterest Facebook LinkedIn
    21stNews21stNews
    • Home
    • Moroccan News
    • Industry & Technologies
    • Financial News
    • Sports
    Subscribe
    21stNews21stNews
    Home»Industry & Technologies»Long-Time HODLer Says $3M Worth of Tokens Were Stolen From His Cold Wallet
    Industry & Technologies

    Long-Time HODLer Says $3M Worth of Tokens Were Stolen From His Cold Wallet

    abdelhosni@gmail.comBy abdelhosni@gmail.comOctober 19, 20254 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An American retiree says more than $3 million in XRP vanished after he checked Ellipal’s mobile app on Oct. 15 and saw his balance gone, a discovery that spurred an on-chain tracing effort by pseudonymous analyst ZackXBT.

    CoinDesk has not independently verified the investor’s identity, balances, or the complete on-chain path. The account comes from several YouTube videos posted since Oct. 15, Ellipal’s public statement on Oct. 18, and ZackXBT’s Oct. 19 X thread.

    What the victim says happened

    The investor, who identified himself as Brandon, said he lives in North Carolina, is 54, and that his wife, 60, is also retired. He said the XRP position was almost their entire retirement savings and that they had planned to buy a house in Las Vegas.

    He said he had been accumulating XRP since 2017 and previously held more but sold some for living expenses. In his YouTube videos, he said he discovered the theft by checking the Ellipal app on Wednesday, Oct. 15, and then determined the drain occurred on the previous Sunday, Oct. 12.

    He described two 10-XRP test pulls around 11:15 a.m. Eastern time, followed by a sweep of about 1,209,990 XRP to a newly created address, then rapid fan-out across dozens of wallets and eventually hundreds. He said smaller balances of other assets, including roughly $1,000 in XLM and about $900 in FLR, remained.

    He said he filed with the FBI’s Internet Crime Complaint Center and contacted local authorities, but struggled to reach specialized cyber units quickly. He said he does not know precisely how the funds were taken from the hot wallet.

    Ellipal’s explanation and the cold-to-hot confusion

    Ellipal said on Oct. 18 that its review indicated the user had imported the hardware wallet’s seed phrase into the Ellipal mobile app, which would recreate the wallet on an internet-connected device.

    In an email to the user, Ellipal explained that if a cold wallet’s seed is used on a phone or tablet, the seed and resulting private keys would be stored on that device, effectively making it a hot wallet and greatly reducing security.

    Brandon said he had Ellipal’s app on both an iPhone and an iPad. He mentioned that the iPhone app showed a blue background, which Ellipal told him denotes a cold-wallet connection, and the iPad app showed an orange background, which Ellipal told him indicates a hot wallet.

    Ellipal emphasized that its hardware devices are air-gapped and said it has not seen thefts originate from the hardware itself. The company’s account points to user error, though it does not by itself prove how the compromise occurred.

    Where the funds reportedly went, per ZackXBT’s investigation

    In an Oct. 19 thread, ZackXBT said he identified the theft address by matching the video’s timing and amounts. He reported that the attacker created more than 120 Ripple-to-Tron orders on Oct. 12 using Bridgers, a swap service formerly known as SWFT. He noted that some block explorers label those hops as “Binance” because Bridgers uses the exchange for liquidity.

    He said the funds consolidated on Tron at a wallet TGF3hP5GeUPKaRJeWKpvF2PVVCMrfe2bYw and by Oct. 15 were dispersed to over-the-counter brokers adjacent to Huione, an online marketplace in Southeast Asia that has been cited in recent public actions by U.S. authorities. CoinDesk has not independently reproduced the full tracing or confirmed the ultimate recipients.

    Recovery odds and user takeaways

    ZackXBT cautioned that most “recovery” firms are predatory, often producing superficial reports while charging high fees. He said quick reporting to credible investigators and compliant platforms can improve the odds of flags or freezes, but recoveries are rare once funds move through cross-chain swaps and OTC venues.

    For users, the core lesson is straightforward: if the goal is cold storage, do not type a hardware wallet’s seed into a mobile or desktop app. Use a distinct seed for any hot wallet and consider a BIP39 passphrase for high-value cold storage.

    Brandon said the loss wiped out what he considered the couple’s retirement plan. He said he shared his experience to warn others and to seek guidance, while acknowledging the chances of recovery are low.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleFernandes says frustrated Anfield helped Manchester United
    Next Article Two decades after it filed bankruptcy, America’s beloved 90s Mexican chain Chi-Chi’s is making a comeback
    abdelhosni@gmail.com
    • Website

    Related Posts

    Industry & Technologies

    OCP Group, IAEA Partner to Boost Sustainable Agriculture and Food Security OCP Group, IAEA Partner to Boost Sustainable Agriculture and Food Security

    February 6, 2026
    Industry & Technologies

    Morocco Expects Heavy Rain, Thunderstorms, and Strong Winds Through Sunday Morocco Expects Heavy Rain, Thunderstorms, and Strong Winds Through Sunday

    February 6, 2026
    Industry & Technologies

    US, Iran Talks End ‘For Now’

    February 6, 2026
    Top Posts

    How Google Gemini Helps Crypto Traders Filter Signals From Noise

    August 8, 202524 Views

    DC facing $20 million security funding cut despite Trump complaints of US capital crime

    August 8, 202521 Views

    DeFi Soars with Tokenized Stocks, But User Activity Shifts to NFTs

    August 9, 202520 Views
    News Categories
    • AgriFood (105)
    • Financial News (1,330)
    • Industry & Technologies (1,245)
    • Moroccan News (1,284)
    • Sports (1,314)
    Most Popular

    Saudi Arabia Suspends Contracts With 1,800 Foreign Umrah Travel Agencies Saudi Arabia Suspends Contracts With 1,800 Foreign Umrah Travel Agencies

    February 3, 20263 Views

    Tangier-Tarifa Ferry Links Suspended Due to Storm Leonardo

    February 2, 20263 Views

    Severe Weather Alert as Snow, Heavy Rain Hit Morocco

    February 1, 20263 Views
    Our Picks

    Stoppage-time goals in the Premier League are out of control

    October 26, 2025

    LIVE: Ecclestone, Bell back as England bat; Renuka in for India

    October 19, 2025

    Moroccan Health Expert Says Virus Has Undergone Changes Contributing to Faster Spread

    December 14, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    • Home
    • About Us
    • Privacy Policy
    © 2026 21stNews. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Go to mobile version