IM·WATCHING LIVE source local node ledger chain --:--:-- UTC
Live forensic surveillance · XRP Ledger · updated every 25s

I'm watching.

A wallet-drainer operation is stealing XRP through fake NFT "claim" sites. Its cluster is under continuous public watch — every figure below is read live from a full-history XRP Ledger node, and every detection is written to a tamper-evident evidence log. Victim addresses are never published.

Stolen (external → collectors)
XRP · victim inflows only
Victims observed
counts only — no addresses
Collectors seeded by funder
≈ targets set up
XRP held by cluster now
live balance sum

01 · Live

Live watch

The event feed streams detections as the node confirms them, graded by severity. The wallet panel shows each cluster address live — a green beacon means we heard from the ledger within the last minute. Highest-value signals: the funder seeding a new collector, and any tagged cash-out (where a real identity attaches).

Detection feed streaming
--:--
connecting to node…
Cluster under watch

What trips an alert — and how loud

02 · For victims

Are you affected?

We do not publish victim addresses — doing so would hand a target list to follow-up "recovery" scammers. Instead, check your own address privately below. If it appears in what we've observed crossing the cluster, you'll get the transaction hashes you need for your own IC3 / exchange report.

Your address is sent only to this node for the check and is never stored or shown to anyone else. A "not found" is not a clean bill of health — we only see what has touched the watched cluster.

03 · Mechanism

How the drain works

A phishing site clones the XRPL marketplace xrp.cafe and tricks a victim into signing one transaction — an NFT buy offer. The attacker accepts it seconds later. Two transactions, both on-chain; click either hash to verify. The victim address is withheld.

04 · The trail

Where it goes

Stolen XRP is swept through single-use and pooling wallets within seconds. Amounts commingle at the pool layer; this is the direct successor chain.

05 · The operation

Three tiers, one root

The cluster is structured. Tier 3 is the funding wallet — the identity anchor that persists across campaigns. It seeds Tier 1 single-use collector wallets (one per victim), whose proceeds funnel into Tier 2 consolidation hubs and out to custodial cash-outs. Watching Tier 3 is an early-warning siren: each new address it funds is, in all likelihood, a new target being set up.

Tier 3 — the funder (identity anchor)

Address
Collectors seeded
distinct Tier-1 wallets
Behavior
Funds a throwaway collector ~seconds before each drain; sweeps proceeds; recycles.

Auto-discovery

Any address the funder pays is added to the watch as a candidate Tier-1 (unconfirmed). Significant transfers to any new address extend the net automatically, so the watcher follows the money as it layers.

06 · Cluster map

The shape of the operation

Tier 3 (the funder) at the root, seeding Tier 1 collectors, funnelling through Tier 2 hubs, exiting at custodial cash-outs. Live balances; the collector column is aggregated because it is continuously churned.

07 · Cash-out

The exit ramps — where a real name exists

The cluster peels funds into deposit addresses carrying destination tags — the fingerprint of a custodial service. The tag is a specific customer identifier: the one point in the chain where a real identity is on file, reachable by the service or by subpoena.

08 · The bait

Phishing infrastructure

Impersonated brands and drainer domains are listed as text, deliberately not as clickable links.

09 · Domain radar

Catching the next domain before it takes anyone's money

Drainer domains are registered and certificated hours before deployment. This watches certificate-transparency logs for freshly issued certs whose names impersonate XRPL brands (xaman, sologenic, xrp.cafe, xrpl, firstledger, xpmarket, bithomp…). New matches from the last few days appear below, as text — never as clickable links.

certificate-transparency source: checking…

10 · Integrity & export

Tamper-evident, and machine-readable

Every detection is written once to an append-only log, each record hash-chained to the last (sha256(previous_hash + record)) with full provenance — which node served the data and the ledger height it was current to. The chain tip below is the fingerprint of the entire record set; publish it somewhere timestamped and it proves retroactively that these records existed as of that moment.

Evidence chain tip · 0 records
sha256(prev_hash + record_content) · append-only · never mutated on reorg (validated ledgers are final)

Daily digest — the chain tip, timestamped

loading…

Generate a detective-ready report packet

Produce a print-ready incident report (narrative, transaction table, money trail, cluster, raw-JSON appendix) for any address. Save as PDF from your browser's print dialog.

11 · Provenance

Read the ledger yourself

This site trusts no screenshots. Balances and transactions are read live from a full-history XRP Ledger node on this server — not the production validator, and not any third-party API. Findings are stated as observed on-chain facts: no names, no attribution to individuals.

Data source: local full-history rippled/xrpld node · JSON-RPC. Stolen total counts only external inflows to Tier-1 collectors; cluster-internal movement is tracked separately as flow ( XRP internal so far this session). USD figures are approximate conversions at time of theft. On-chain analysis identifies addresses, flows and cash-out points; it does not name an account holder — the "Union Chain" domain is self-declared and unverified.