Chris Larsen Hack

Reported loss $112M
Access Control

What happened

In January 2024, four personal XRP wallets belonging to Ripple co-founder Chris Larsen were accessed without authorization. The incident concerned Larsen’s personal holdings, not a compromise of Ripple’s corporate systems.

Technical root cause

Public reporting supports unauthorized access to personal wallets but does not establish whether the cause was a leaked key, account takeover, or another method. The root cause is therefore unknown.

How it happened

  1. Unauthorized transfers were detected from four personal XRP wallets.
  2. Larsen said exchanges and law enforcement were notified.
  3. Binance reported freezing approximately $4.2 million in XRP linked to the incident.

Protocol details

Classification Other
Protocol Type Exploit/Access control
Affected asset / contract XRP

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.