XPR Network block producer ProtonNZ has issued an urgent warning about a phishing campaign operating through xprdrop.com. The fraudulent site imitates an XPR airdrop and tricks users into signing away account authority, allowing an attacker to retain access after the initial interaction. ProtonNZ disclosed the active campaign on August 3 and released a dedicated cleanup tool for affected accounts.
The attack does not rely on stealing a private key or exploiting the blockchain’s consensus software. Victims authorize the drainer themselves by approving a disguised account-permission transaction. Receiving the unsolicited XPRDROP token or seeing its promotional memo is not enough to compromise a wallet; the danger begins when a user visits the linked site, connects an account and signs the supposed claim.
The fake XPRDrops website does not give you an airdrop. When you approve its wallet request, it creates a new permission named claim, controlled by xprgrant@active.
That permission can be linked to:
❌ Transfer your XPR and other tokens
❌ Unstake your XPR
❌ Claim the unstaked… pic.twitter.com/M5LXyS4ky6— protonnz ⚛️ (@protonnz) August 2, 2026
Fake Claim Creates Persistent Account Access
The malicious transaction creates a custom permission, commonly named claim, and assigns control to the external authority xprgrant@active. That delegated permission can remain active until it is explicitly removed, enabling repeated transactions whenever new liquid assets reach the account.
XPR Network supports named, hierarchical permissions that can be linked to particular contracts or actions. The same architecture that enables controlled delegation can become dangerous when a user approves an unknown authority. A linked permission may authorize token transfers and, depending on its configuration, unstaking-related actions without requiring another signature from the victim.
ProtonNZ said the attacker can transfer available tokens within seconds and may return later if previously staked assets become liquid. The campaign is therefore a persistent permission-delegation attack rather than a one-time fraudulent transfer. Users should not assume an account is safe merely because its remaining balance has not yet moved.
The incident does not indicate that XPR Network itself has stopped operating or that every wallet is exposed. Risk is concentrated among accounts that signed the fraudulent authorization request, separating the phishing campaign from a protocol-wide exploit or validator failure.
Revoking the Permission Is the Primary Fix
Affected users can inspect their accounts through an XPR block explorer or ProtonNZ’s read-only audit tool to find unfamiliar permissions and linked actions. The malicious authorization must be unlinked and deleted before assets are unstaked or new funds are deposited. ProtonNZ’s cleanup utility builds the required unlinkauth and deleteauth actions into one transaction that the user reviews and signs.
ProtonNZ says key rotation is generally unnecessary because the campaign does not obtain the victim’s private key. Removing the delegated permission terminates the attacker’s authorized access, provided no other unknown authorities or compromised keys are present. Users should verify that any cleanup service is hosted on the official ProtonNZ domain and review every action before signing.
The warning reinforces a critical security distinction: wallet connections are not always limited to approving a single payment. An updateauth or linkauth request can change who controls future account actions, making the transaction far more consequential than an ordinary token claim.
The response is focused on account-level remediation rather than network recovery. Users who interacted with xprdrop.com should audit their permissions immediately, while anyone who only received the unsolicited token can leave it untouched and avoid the embedded link.
