According to PANews, a retired American from North Carolina, Brandon Laroque, reported on October 15 that over $3 million worth of XRP disappeared from his Ellipal mobile application. Laroque acknowledged that he does not expect to recover the funds but hopes his experience serves as a cautionary tale about keeping cold wallets truly offline. Following the incident, he reported it to the FBI and other authorities but faced challenges in quickly reaching professional investigators.
On October 18, Ellipal issued a statement revealing that an internal review found Laroque had entered his hardware wallet's seed phrase into the application, converting his cold storage into a hot wallet. The company clarified that the app uses a blue background for cold wallets and orange for hot wallets. Ellipal emphasized that no theft had occurred on their part, attributing the incident to user error. While they could not verify the technical details of the theft, they confirmed that entering the seed phrase nullifies all security measures.
Blockchain investigator ZachXBT analyzed the situation, noting that the stolen XRP was aggregated on the Tron network and then transferred to multiple over-the-counter brokers associated with Huione. The funds have since been dispersed across numerous addresses, making recovery nearly impossible.