The Seoul Metropolitan Police Agency's Cyber Investigation Unit has dismantled a sophisticated crypto investment fraud ring that created a fake staking website impersonating Flare Network—a popular smart contract platform closely integrated with the XRP ecosystem.

Over an eight-day window, the fraudsters stole 3.4 million XRP (valued at ~$8.5 million) from 71 investors. Police investigations have since traced a total of $18.8 million (17.3 billion KRW) in illicit transactions moving through interconnected laundering wallets.

To build trust, the scam ring orchestrated a high-production media campaign. They hired actors to pose as former exchange developers in YouTube videos and published fake news articles, promising guaranteed monthly staking returns of up to 1.8% for holding and depositing XRP. The fake platform was intentionally launched to coincide with legitimate Flare Network product releases to maximize user confusion. The Pipeline to Crypto Theft

This incident underscores how brand spoofing and high-production social engineering serve as primary entry points for draining retail funds:

1. Brand Impersonation & Launch Alignment

By replicating Flare Network’s UI, logos, and messaging, the scammers bypassed the usual caution of retail holders. Launching the phishing site simultaneously with official protocol updates meant that users searching for new staking features were easily directed to the spoofed domain.

2. Fake Staking Ingress & Direct Asset Sweeping

When victims deposited XRP to the fake site’s address expecting staking rewards, no smart contract yield mechanism existed. The deposited assets were immediately routed to automated sweeper wallets, which fragmented the funds across multiple global exchanges to evade detection.

3. Actor-Driven Social Proof

The use of hired actors, fake interviews, and sponsored content represents a dangerous trend in Web3 scams. Scammers are moving beyond traditional phishing emails toward polished video campaigns that create a false sense of legitimacy, convincing users to willingly sign malicious transactions or transfer funds directly to drainer addresses.