XRPL · Verification guide
Verify before you trust
The XRP Ledger's openness is its strength — anyone can issue a token or launch a "protocol." That also means impersonators, inflated numbers and high-yield schemes sit right next to the real thing. The good news: on a public ledger, the truth is verifiable. Here's how to check any XRPL token or protocol yourself in a few minutes — or paste an issuer address below and we'll check it for you.
Auto-checks the bidirectional xrp-ledger.toml, on-chain issuance and the XRPScan directory — instantly.
The golden rule: "on-chain" means there's evidence
A real on-chain project can prove it. It publishes its XRPL issuer address, its transactions are visible on a block explorer, and its code is open. If a site claims to be "fully on-chain" but gives you no address, no contract, no transaction hashes and no way to check — that absence is the answer. "Trust me, it's on-chain" with nothing to verify is the single most common tell.
The 5-step verification checklist
1 · Demand on-chain evidence
Find the issuer address or contract. No address, no transaction hashes, no explorer link → no proof. A legitimate project handling real value puts its accounts front and centre.
2 · Verify issuer identity — bidirectionally
A real issuer's identity is confirmed both ways: the project's domain hosts an xrp-ledger.toml that lists the issuer address, and the address points back to that domain. An on-chain Domain field a wallet sets on itself, or a vanity prefix (e.g. rBLaCK…), proves nothing — both are trivially spoofable.
3 · Read supply & holder concentration
Pull circulating supply on-chain with gateway_balances. Then check who holds it. A token can show a huge supply that sits entirely in the issuer's own wallet — "represented" value, not real adoption. Distributed value across many independent holders is what counts.
4 · Sanity-check the claims
Compare the story to reality. When was the domain registered (a site weeks old claiming a year-old audit is impossible)? Are the yields plausible — or 40–80%+ APY? Does it claim tech that doesn't exist on mainnet, like "Hooks" (Hooks run on the Xahau sidechain, not XRPL mainnet)?
5 · Verify audits & team
Real audits are published reports you can open and read, linked from the auditor too — not just a logo. Anonymous teams, principal lock-ups that stop you withdrawing, and "insurance" that can't be confirmed are the markers of a scheme, not a protocol.
Red flags we've documented
We maintain a curated, on-chain-verifiable list of XRP Ledger addresses issuing counterfeit RWA tokens — fake tokenized funds, treasuries and institutions (BlackRock, JPMorgan, OUSG, RLUSD and more) that set a company's domain they don't control and fail bidirectional verification. Every entry is reproducible on-chain.
See all flagged issuers →How xrpl.fi applies this
Every issuer on the dashboard is run through this same process: supply read live via gateway_balances, identity confirmed against the issuer's domain xrp-ledger.toml, and only distributed, verifiable value counted. Impersonators, dust and represented-only tokens don't make the list — so if it's on xrpl.fi, the issuer is real.
See verified data
Every tracked real-world asset on the XRP Ledger, each issuer identity-verified on-chain — supply, holders and 24h volume, live.