A fraudulent staking website posing as Flare Network stole 3.4 million XRP from 71 investors in South Korea, with losses potentially exceeding $18 million as authorities investigate further victims and frozen assets.
South Korean authorities have arrested three suspects linked to a sophisticated phishing operation that impersonated the Flare Network and siphoned off 3.4 million XRP, worth $8.5 million at the time, from 71 investors in October 2025. According to police in Seoul, the fraudulent site, Fxrpntwork(dot)com, operated for just eight days before shutting down, but the scale of the losses and the tactics used have raised new concerns about crypto scam sophistication and investor vulnerability.
Fake FXRP Investment Scheme
The scam was timed to exploit the real launch of the FXRP token, leveraging heightened media attention and public interest in the legitimate Flare Network. Operators of the fake site promised monthly returns of 1.5% to 1.8% with principal protection, luring victims to transfer funds from domestic exchanges through overseas platforms and into wallets controlled by the fraudsters. Police say the group did not rely solely on the website: they seeded misleading information across Naver blogs, online news outlets, and Wikipedia, and even paid a 34-year-old to appear in YouTube videos endorsing the fake project. That individual now faces fraud charges.
Three of the four main suspects, all 29 years old, have been apprehended. Two were referred to prosecutors on aggravated fraud charges, while a third was arrested after returning from abroad. The fourth remains at large overseas, with an Interpol Red Notice requested. None of the suspects have been publicly identified, and no trial has yet taken place.
Police Trace Millions in Crypto
Police have executed 54 search and seizure warrants and traced 27.3 billion won, about $18.8 million, through wallets linked to the operation, freezing 17.3 billion won in assets. Roughly 10 billion won was moved during the investigation and remains unrecovered, suggesting the number of victims and total losses may be higher than currently confirmed.
Flare Network, the legitimate blockchain project impersonated in the scam, launched in early 2023 and reported more than $160 million in total value locked as of March 2026, with over 887,000 active addresses. The real project has no connection to the fraudulent site. South Korean police have pledged a zero-tolerance approach to crypto fraud and urged investors to verify staking opportunities through official channels before transferring funds.
The incident follows a broader trend. Blockchain analytics firm Chainalysis estimated that global crypto scam and fraud losses reached $17 billion in 2025, with criminal groups increasingly using impersonation and AI tools to scale their operations.
Global Phishing Risks
While the Flare Network scam targeted South Korean investors, the risks of phishing and impersonation schemes are global. U.S. users, exchanges, and wallet providers face similar threats, especially as scammers adapt their campaigns to exploit new token launches and media cycles. The case also highlights the importance of cross-border cooperation in crypto investigations, as suspects and funds can move rapidly between jurisdictions.
In a related development, the expansion of mining infrastructure, such as Fortitude's new 12-megawatt Zcash facility in Nebraska, demonstrates how legitimate blockchain projects continue to grow even as the industry contends with persistent security risks. For more on how mining operations are evolving, see this report on Zcash mining expansion in Nebraska.
According to data from Flare Network, the protocol's total value locked surpassed $160 million as of March 31, 2026, with more than 887,000 active addresses recorded on the network. Chainalysis reported that global crypto scam and fraud losses reached approximately $17 billion in 2025, underscoring the scale of the threat facing both retail and institutional participants in the digital asset sector.
Phishing scams in the cryptocurrency sector often exploit the complexity of blockchain transactions and the difficulty of verifying project legitimacy. Attackers may use cloned websites, fake social media accounts, manipulated search results, and paid endorsements to appear credible. Once funds are transferred to a scam-controlled wallet, recovery is extremely difficult because most blockchain transactions are irreversible and addresses can be difficult to connect to real-world identities. Offers promising guaranteed returns or requiring funds to be routed through unfamiliar platforms are common warning signs, making verification through official project channels essential before any transfer.