XRP Healthcare says 4,011 wallets lost $452,000
XRP Healthcare said 4,011 XRPH Wallet accounts were affected by unauthorized transactions beginning Sept. 3, with approximately $452,000 in XRP and related assets removed.
XRP Healthcare said 4,011 wallets lost approximately $452,000 during unauthorized transactions beginning September 3, 2026. The project traced stolen assets to one Ethereum wallet and contacted exchanges about freezing funds. Users were told to stop using XRPH Wallet while the development team investigated the breach. Independent investigators attributed the compromise to seed phrases transmitted through a staking-related server request process. Former Ripple developers said earlier grant reviews identified project risks, allegations XRP Healthcare publicly disputed.
XRP Healthcare traces stolen funds to Ethereum
XRP Healthcare initially confirmed unauthorized transactions involving XRP, XRPH, XRPHAI and other assets. The company instructed users to stop using XRPH Wallet until further notice while its developers investigated the compromise.
A subsequent update placed the affected wallet count at approximately 4,011 and the estimated loss at $452,000. The company said investigators traced the assets to one Ethereum address and contacted exchanges and other parties about freezing or recovering them.
Independent on-chain researcher Handy Andy reported that the affected accounts lost 267,664 XRP and approximately 23.2 million XRPH tokens. The researcher said the assets were converted into roughly 445,198 DAI on Ethereum and remained in the destination wallet at the time of the update.
Investigators examine a possible seed phrase leak
Independent investigators attributed the XRPH Wallet breach to its staking function. Their analysis alleged that activating staking caused users' seed phrases to be transmitted to a remote server.
XRP Healthcare had not published source code, server logs or an independent forensic report confirming that explanation when this article was prepared. The seed phrase exposure therefore remains a researcher finding rather than a company-confirmed root cause.
A seed phrase provides control over every private key generated by a wallet. Anyone obtaining it can reproduce the wallet and authorize transactions without accessing the victim's phone. Crypto.news previously explained how seed phrases function as master recovery keys and why they should never leave the user's secure environment.
The reported failure resembles a July incident in which a compromised software package transmitted private keys through a fraudulent telemetry function. However, no evidence currently connects the two cases or their perpetrators.
Former Ripple developers revive earlier concerns
The breach prompted public criticism from developers previously associated with Ripple and the XRP Ledger ecosystem. BiasGoose said he had rejected an earlier grant application from the project because the application showed what he considered clear warning signs.
He later alleged that the team had misrepresented partnerships in its application. Hazard Cookie said earlier reviewers had identified risks that were not publicly visible at the time.
Former Ripple developer Matt Hamilton also referred to the project's earlier reputation within the community. These statements represent the developers' accounts. Public grant records or complete audit documents substantiating every allegation were not available.
XRP Healthcare rejected the tone of the criticism and accused former developers of celebrating another team's losses. Its response called that conduct "genuinely pathetic" and said the company had put its own reputation and capital at risk. The exchange did not resolve the technical questions surrounding the wallet.
-- Price
Users need new wallets before moving remaining assets
XRP Healthcare must now establish the precise entry point, determine when seed information may have been exposed and identify which application versions were affected. A full postmortem should also explain whether the reported server retained seed phrases and who could access them.
Users who created or imported seed phrases into the affected application cannot rely solely on an app update if those phrases were exposed. Remaining funds should be transferred to newly generated wallets using trusted software. Reusing an old seed would preserve the attacker's access.
The company has not announced a reimbursement program or recovery deadline. It also has not confirmed whether law enforcement or any exchange successfully froze the traced funds. Users should rely on official channels and reject unsolicited recovery offers requesting keys, seed phrases or payments.
The incident follows a wider rise in wallet and infrastructure compromises. As crypto.news reported, operational security failures caused 74% of stolen funds during the first half of 2026. Separately, Ripple's recent audit program identified 96 vulnerabilities across proposed XRPL amendments, showing the value of testing before software reaches users.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Jewellburg Operates Cyber Espionage and Cryptocurrency Fraud Simultaneously

Nikita Bier Bids Farewell to X Product Team: What Has He Left Behind?

800x Golden Dog: 'Card Draw' Saves NFT Trading

Cookie DAO has completed an algorithm update to optimize SNAPS earning mechanics

This Week's Key News Preview | The Federal Reserve Announces New Interest Rate Decision; The U.S. Releases February PPI Data

Cookie DAO: Launchpad Officially Launches Today, First Token Sale Scheduled for Monday

Cookie DAO: Will Distribute Additional COOKIE Tokens to Openledger Snappers

CZ’s Kyrgyzstan visit highlights why state backing cannot guarantee a stablecoin exit

As Polymarket and Others Step into the 'Background': The Second Half of Prediction Markets Beyond Exchanges?

Polymarket Report for the First Half of 2026: High-Frequency Traders or Super Forecasters?

Meta Creates AI Filter to Select Experiments Before Spending GPU Hours

IFM Launches K2 Horizon, an Open AI Family with Up to 375 Billion Parameters

Nepal Requests $2.5 Billion from UN Climate Fund After Devastating Floods

Amazon Cargo Plane Crashes on Landing in Miami, Leaving Several Injured

How to mine Bitcoin: A beginner’s guide to mining BTC-Top 4 cloud mining sites in 2026
![[Editorial] Freedom: More Important Than Democracy](/public-static/29_4631d65680.png?format=avif)
[Editorial] Freedom: More Important Than Democracy

Economy: China Injects $54 Billion into Its Financial System

Baidu Stock Connect Access: Can Shares Rise by 20% in a Month?

Can AI Preferred Networks chips really beat Nvidia by 10 times?

AI vs Human Crypto Trading Rewards on WEEX in Sep 2026

Are AI Trading Apps Good for Crypto? Inside the WEEX AI Wars Hackathon

Trump's Approval Drops to 33% and Pressures Markets Ahead of Midterms

Mexico: A $1.5M Bitcoin Wallet Linked to the Murder of a Musician and His Family

Cryptocurrencies: A Family Wrongly Kidnapped and Assaulted Near Rennes

TRON Industry Weekly Report: Non-Farm Payrolls Lean Hawkish but CPI Will Determine If BTC Can Hold Above 80,000, Detailed Analysis of KOR Protocol for Digital Content and IP Assetization

Meme Coins Directly Paired with Stock Tokens: The Real Reason Behind Robinhood Chain's Surge

Is AI Trading Real or Hype? WEEX AI Wars II Explained

Rare Meeting During Fed's Quiet Period Sparks Controversy Over Bowman and Powell's Schedules

Blockchain Capital Partner: Tokenization is the Container of Capital Markets









