XRP Healthcare XRPH Wallet Breach
A flaw in XRP Healthcare's XRPH Wallet app exposed users' seed phrases, letting an attacker drain 4,011 wallets of roughly 267,664 XRP and XRPH tokens worth about $452,000 on the XRP Ledger.
- Date
- Victim
- XRP Healthcare
- Chain(s)
- Status
- Funds Stolen
On September 3, 2026, XRP Healthcare saw 4,011 user wallets drained of roughly 267,664 XRP and about 23.2 million XRPH tokens — approximately $452,000 — after a flaw in its XRPH Wallet application exposed users' secret keys.
What happened
XRP Healthcare, a healthcare-focused project building on the XRP Ledger, distributed a self-custody mobile wallet called XRPH Wallet. Beginning around 22:07 UTC on September 3, an attacker systematically emptied thousands of wallets over roughly three hours — a pattern only possible if the attacker held the users' keys directly.
Independent researchers concluded that activating the wallet's staking feature caused users' seed phrases to be transmitted to a remote server, handing whoever controlled that server the ability to reconstruct every affected private key. Analysts also pointed to a longstanding weak key-generation flaw — improperly formatted entropy fed into the ledger's key derivation, shrinking the effective key space. XRP Healthcare did not publish source code or a forensic report confirming a single root cause.
The attacker consolidated the loot, bridged it out through NEAR Intents onto Ethereum, and converted the holdings into roughly 445,198 DAI, most of which sat unmoved in a single address at the time of reporting.
Aftermath
XRP Healthcare told users to stop using XRPH Wallet immediately, contacted exchanges about freezing funds, and later announced it was winding down operations entirely. No reimbursement program had been confirmed, and a public dispute broke out between current and former developers over responsibility.
Why it matters
Custodial-key exposure is one of the deadliest wallet failure modes, because it defeats every on-chain protection at once — echoing Slope Wallet, which likewise shipped users' seed phrases to a central server, and Atomic Wallet. A wallet that ever transmits a seed phrase off-device has already failed: self-custody means the secret must never leave the user's hands. The incident was small in dollars but total for its 4,011 victims, and it ended the project.
Sources & on-chain evidence
- [01]crypto.newshttps://crypto.news/xrp-healthcare-says-4011-wallets-lost-452000/
- [02]kucoin.comhttps://www.kucoin.com/news/flash/xrp-healthcare-wallet-vulnerability-leads-to-450-000-theft
- [03]99bitcoins.comhttps://99bitcoins.com/news/altcoins/xrp-healthcare-hack/
- [04]cryptotimes.iohttps://www.cryptotimes.io/2026/09/07/crypto-hacks-cross-322m-in-septembers-first-week-as-liquid-network-alone-loses-320m/
- [05]en.coinotag.comhttps://en.coinotag.com/xrp-healthcare-wallet-hack-drains-267000-xrp-4000-wallets