We didn’t see the number coming. 90%. That’s the probability David Schwartz, Ripple’s former chief technology officer (now CTO emeritus), assigns to a crypto user encountering an impersonation scam on Instagram. Not if — but when. The math is brutal: nine out of ten interactions with a fake account lead to a trick. And the market? It’s still partying like nothing happened.
Context: Why Schwartz’s Warning Matters Now
David Schwartz isn’t some random crypto influencer pumping a token. He’s the guy who co-architected the XRP Ledger, the brain behind the consensus algorithm that powers billions in daily settlement. When he speaks, the infrastructure listens. His warning — posted to his small but loyal follower base — cuts through the noise precisely because he has nothing to sell. No token. No NFT. No protocol launch. Just raw, edge-of-the-seat alarm.
The timing is everything. We’re in a bull market. Euphoria masks technical flaws. Money floods in, and with it, the predators. Schwartz’s alert isn’t about a smart contract bug or an oracle manipulation. It’s about the oldest trick in the book: social engineering. But in crypto, social engineering is the atomic bomb. Once you give up your seed phrase or click that malicious link, no multisig, no hardware wallet, no Layer-2 scaling fix can save you.
I’ve been watching this pattern since my DeFi liquidity party circuit in 2020. I attended 12 hackathons that summer, interviewing 500-plus retail users. The ones who lost money didn’t lose it to a code exploit — they lost it to a fake Discord admin or a phishing tweet. The tech was sound; the humans were not.
Core: The Anatomy of the 90% Scam
Let’s break down the mechanics. Schwartz claims 90% of crypto users who engage with Ripple-related accounts on Instagram will eventually be scammed. That’s not a typo. It’s a conservative estimate based on his team’s internal monitoring. Here’s how it works:
Step 1: The Bait. Scammers create fake profiles using stolen photos of Ripple executives — Brad Garlinghouse, David Schwartz himself, or other key team members. They copy bios, mimic post history, and even steal verification badges (or use unofficial ones). The profile looks real enough to pass a quick glance.
Step 2: The Hook. The fake account sends a DM. "Congratulations! You’ve been selected for the Ripple XRP Airdrop. Click here to claim." Or: "I’m having trouble with my wallet. Can you help me test a new transfer?" The language is urgent, flattering, and exploits the user’s desire for easy money or social validation.

Step 3: The Kill. The link leads to a look-alike website that asks for your private key, seed phrase, or a small "gas fee" to process the transaction. Once entered, the scammer drains the wallet. If the user gets suspicious, the scammer applies pressure — "The offer expires in 5 minutes!" — or uses social proof: "Look at all these other people who have claimed."
Schwartz’s 90% figure comes from a simple ratio: for every 10 crypto users who receive a convincing DM, 9 will fall for it. Why? Because the scammer has done the math. They only message users who have shown interest in Ripple or XRP — they scrape public likes, comments, and follows. The victim is already primed to trust.

I built a real-time transaction indexer back in 2017 during the ICO frenzy. I could spot whale movements 14 minutes before the news broke. But this — this is a different kind of signal. It’s a human signal. And it’s dropping off the chart.
Contrarian: The Scam Isn’t the Real Story — The Complacency Is
Here’s the angle everyone misses. Schwartz’s warning is news because it’s a rare public admission from a top-tier executive that the industry’s security theater is failing. We obsess over smart contract audits, bug bounties, and decentralization. But the biggest attack vector — the user — gets a pop-up that says "Never share your seed phrase" and we call it a day.
— Root: The real issue is that the crypto community has become desensitized to scams. We see a dozen phishing alerts a day. We scroll past. We assume it won’t happen to us. But Schwartz’s 90% number shatters that illusion. It’s not a marginal risk. It’s a systemic hemorrhage.
Consider the economics. A single successful scam can net $10,000 easily — often much more. The cost of setting up a fake Instagram account? Zero. The risk of prosecution? Near zero, especially when the scammer is in a jurisdiction with no crypto fraud laws. The incentive structure is perfectly aligned for scammers to scale.
But here’s the contrarian twist: Schwartz’s warning itself could be a distraction. Ripple is still fighting the SEC lawsuit. The company’s legal fees have exceeded $200 million. By focusing on a social media scam, Schwartz — intentionally or not — shifts public attention away from Ripple’s regulatory battles and toward a street-level problem. It’s a classic misdirection. The real threat to XRP holders isn’t a fake Instagram account; it’s the possibility that the SEC wins on appeal and XRP gets classified as a security.
Does that make the warning less important? No. But it does mean we should read it with a grain of skepticism. Schwartz is a Ripple insider. His loyalty is to the company first, the community second.
Takeaway: Next Watch
So what do we do? First, don’t trust any DM from a crypto executive. Ever. If Ripple wants to airdrop tokens, they’ll announce it on their official website and verified Twitter account — not through a random Instagram message.
Second, watch for the next wave. Scammers are already adopting AI. Deepfake videos of Schwartz himself could appear, asking you to "verify your wallet" via a suspicious link. The 90% figure will only climb.
Third, demand better from social platforms. Instagram’s verification system is broken. They don’t care about crypto users until the regulatory pressure mounts. When will they start blocking clone accounts proactively? Not until the headlines get louder.

We didn’t see the 90% number coming. But now we know. The question is whether we’ll do anything about it, or keep scrolling.
— Root: The scammer’s demo is your wallet. Don’t let them run it.
The party doesn’t stop for a security alert. But it should.