XRP Healthcare says 4,011 wallets lost $452,000
XRP Healthcare said 4,011 XRPH Wallet accounts were affected by unauthorized transactions beginning Sept. 3, with approximately $452,000 in XRP and related assets removed.
XRP Healthcare said 4,011 wallets lost approximately $452,000 during unauthorized transactions beginning September 3, 2026. The project traced stolen assets to one Ethereum wallet and contacted exchanges about freezing funds. Users were told to stop using XRPH Wallet while the development team investigated the breach. Independent investigators attributed the compromise to seed phrases transmitted through a staking-related server request process. Former Ripple developers said earlier grant reviews identified project risks, allegations XRP Healthcare publicly disputed.
XRP Healthcare traces stolen funds to Ethereum
XRP Healthcare initially confirmed unauthorized transactions involving XRP, XRPH, XRPHAI and other assets. The company instructed users to stop using XRPH Wallet until further notice while its developers investigated the compromise.
A subsequent update placed the affected wallet count at approximately 4,011 and the estimated loss at $452,000. The company said investigators traced the assets to one Ethereum address and contacted exchanges and other parties about freezing or recovering them.
Independent on-chain researcher Handy Andy reported that the affected accounts lost 267,664 XRP and approximately 23.2 million XRPH tokens. The researcher said the assets were converted into roughly 445,198 DAI on Ethereum and remained in the destination wallet at the time of the update.
Investigators examine a possible seed phrase leak
Independent investigators attributed the XRPH Wallet breach to its staking function. Their analysis alleged that activating staking caused users' seed phrases to be transmitted to a remote server.
XRP Healthcare had not published source code, server logs or an independent forensic report confirming that explanation when this article was prepared. The seed phrase exposure therefore remains a researcher finding rather than a company-confirmed root cause.
A seed phrase provides control over every private key generated by a wallet. Anyone obtaining it can reproduce the wallet and authorize transactions without accessing the victim's phone. Crypto.news previously explained how seed phrases function as master recovery keys and why they should never leave the user's secure environment.
The reported failure resembles a July incident in which a compromised software package transmitted private keys through a fraudulent telemetry function. However, no evidence currently connects the two cases or their perpetrators.
Former Ripple developers revive earlier concerns
The breach prompted public criticism from developers previously associated with Ripple and the XRP Ledger ecosystem. BiasGoose said he had rejected an earlier grant application from the project because the application showed what he considered clear warning signs.
He later alleged that the team had misrepresented partnerships in its application. Hazard Cookie said earlier reviewers had identified risks that were not publicly visible at the time.
Former Ripple developer Matt Hamilton also referred to the project's earlier reputation within the community. These statements represent the developers' accounts. Public grant records or complete audit documents substantiating every allegation were not available.
XRP Healthcare rejected the tone of the criticism and accused former developers of celebrating another team's losses. Its response called that conduct "genuinely pathetic" and said the company had put its own reputation and capital at risk. The exchange did not resolve the technical questions surrounding the wallet.
-- Price
Users need new wallets before moving remaining assets
XRP Healthcare must now establish the precise entry point, determine when seed information may have been exposed and identify which application versions were affected. A full postmortem should also explain whether the reported server retained seed phrases and who could access them.
Users who created or imported seed phrases into the affected application cannot rely solely on an app update if those phrases were exposed. Remaining funds should be transferred to newly generated wallets using trusted software. Reusing an old seed would preserve the attacker's access.
The company has not announced a reimbursement program or recovery deadline. It also has not confirmed whether law enforcement or any exchange successfully froze the traced funds. Users should rely on official channels and reject unsolicited recovery offers requesting keys, seed phrases or payments.
The incident follows a wider rise in wallet and infrastructure compromises. As crypto.news reported, operational security failures caused 74% of stolen funds during the first half of 2026. Separately, Ripple's recent audit program identified 96 vulnerabilities across proposed XRPL amendments, showing the value of testing before software reaches users.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

What Are the Conditions for Success of Data Centers? A Map of AI Data Centers in Korea – Bitplanet

Jewellburg Operates Cyber Espionage and Cryptocurrency Fraud Simultaneously

Nikita Bier Bids Farewell to X Product Team: What Has He Left Behind?

800x Golden Dog: 'Card Draw' Saves NFT Trading

Cookie DAO has completed an algorithm update to optimize SNAPS earning mechanics

This Week's Key News Preview | The Federal Reserve Announces New Interest Rate Decision; The U.S. Releases February PPI Data

Cookie DAO: Launchpad Officially Launches Today, First Token Sale Scheduled for Monday

Cookie DAO: Will Distribute Additional COOKIE Tokens to Openledger Snappers

HotShort to present short-drama RWA model at GWDC Korea 2026

AI Model Gemini Exits Testing and Attacks Three Real Companies

BlackRock Executive: Bitcoin Volatility Halved, Shifting from 'Get-Rich Narrative' to 'Collateral Narrative'

Lemon exits Brazil over crypto licensing costs

Brazil blocks stablecoins from key cross-border payment rail as $1.1 trillion market faces new limits

The Three Words and One Answer from Yesterday's Press Conference: Wall Street is Pondering 'Waller's Approach'

Crypto: The 2026 Ranking of the 36 Most Favorable Countries for Adoption

Follow the Money: Corporate Segment Lull, Kaiko's $57 Million Round, and Several M&A Deals

Crypto VC funding: Kaiko leads $180M week

El Niño Dries Up Dams, Ethiopia Rationing Bitcoin Miners

Best Crypto Exchange in Italy in 2026: What to Choose for Systematic Trading

USDT in Wallets May Be Blocked. What to Do and How to Store Them in Russia

Crypto vs Cash: 3 Clandestine Trading Posts Raided in London

Ethereum's Next Upgrade May Become the Most Significant Catalyst in History
![[Exclusive] Controversy Over Private VIP Event for Virtual Assets... Upbit and Bithumb Claim 'Never Held'](/public-static/21_2c30f7df62.png?format=avif)
[Exclusive] Controversy Over Private VIP Event for Virtual Assets... Upbit and Bithumb Claim 'Never Held'

Ethereum co-founder Vitalik Buterin argues that local AI can protect your privacy without losing speed

XRP ETFs hit a speed bump, but big investors aren’t dumping their tokens yet

This Week's Macroeconomic Highlights: Waller's First Rate Hike, Saudi Arabia Repairs Oil Pipeline Lifeline

Web3 Newsletter: Industry Highlights and Must-See Trends This Week

Cryptocurrency Security Guide: How to Identify and Prevent Social Engineering Attacks

Why SBI just put millions behind a Singapore startup’s stablecoin push










