XRP Healthcare Wallet Hack Drains 267,000 XRP (XRP) From 4,000 Wallets

Attackers drained about 4,000 XRPH Wallet accounts on Sept. 3, moving 267,000 XRP plus millions of tokens to Ethereum, as former Ripple devs flag red flags.

(08:38 PM UTC)
4 min read
AI SummaryAI
  • XRP Healthcare's XRPH Wallet incident on Sept. 3 drained roughly 4,000 user wallets.
  • Attackers moved about 267,000 XRP plus millions of XRPH and XRPHAI tokens.
  • Forensic review found seed phrases were sent to a server during staking activation.
  • Stolen assets were quickly transferred to the Ethereum network.
k7rq2fdm

4,000 Wallets Drained in Three Hours

The XRP Ledger (XRPL) ecosystem was hit by a large-scale security incident on Sept. 3, 2026, when the mobile wallets of XRP Healthcare — a healthcare-focused project on XRPL, formerly known as XRPayNet — were emptied at scale. On-chain data shows roughly 4,000 user wallets lost their balances in approximately three hours, with attackers making off with around 267,000 XRP alongside millions of XRPH and XRPHAI tokens. A portion of the stolen assets was rapidly moved to the Ethereum network, a shift that shows how cross-chain bridges can complicate recovery once funds leave their native chain. Crucially, nothing in the investigation so far points to a flaw in the XRP Ledger protocol itself: the failure sits within the wallet application's architecture, not the ledger's consensus or node infrastructure. That distinction matters for holders of the asset and the project's tokens alike, because XRP and the XRPH Wallet represent separate layers of risk. The event has nonetheless reignited a broader security debate across the XRP ecosystem, with developers and users questioning how self-custody applications built on XRPL handle the most sensitive credential a user owns: the seed phrase.

Seed Phrases Sent to a Server

Forensic review traced the breach to a design flaw at the heart of the app. An independent on-chain analysis published by XRPL.to found that when users activated the staking feature, their seed phrases — the master keys from which all wallet addresses derive — were transmitted to an XRP Healthcare server. The same review linked the majority of drained addresses directly to XRPH Wallet usage. In other words, the private keys most users assume never leave their device were, at least during that flow, sitting on company infrastructure. XRP Healthcare confirmed the unauthorized transactions on Sept. 4 and urged users not to open the app until further notice, saying developers were tracing movements on-chain and coordinating with relevant authorities to freeze and recover the assets. What remains undisclosed is just as important: the team has not yet confirmed whether the server-side exposure was deliberate data collection or an engineering oversight. For readers re-evaluating custody choices, our guide on how to set up a Ripple paper wallet walks through offline key generation, and security researchers widely recommend moving funds to hardware or offline storage whenever an application's key handling cannot be independently verified.

Former Ripple Devs Flag Years of Warnings

The fallout quickly turned into a public confrontation on X. Developer BiasGoose was among the first to comment, saying the drain was not news to him and that he had previously rejected grant applications from the team. In his view, the Uganda-linked medical initiative had displayed red flags from the outset, including what he described as blatant misstatements about partnerships in its funding applications — claims made, he argued, to secure financing and manufacture hype. He added that the product never needed its own token at all, a critique that cuts to the project's entire tokenomics rationale. Former Ripple security figures backed the assessment: Hazard Cookie, previously at Ripple, and developer Matt Hamilton said auditors had documented the project's architectural risks for years, with Hamilton noting there were all red flags when he dealt with the team back in its XRPayNet days. Community members also recalled the project being pushed out during earlier market cycles between 2022 and 2024 amid accusations resembling a rug pull. XRP Healthcare pushed back hard, calling the veterans' conduct unethical and their public gloating over user losses genuinely pathetic; BiasGoose replied that, unlike the app's creators, he never took risks with other people's money.

Protocol vs. Application: The Real Lesson

The on-chain record is the most load-bearing document in this story: the forensic analysis we reviewed shows seed phrases traveling to a remote server, a fact that independently confirms the breach vector regardless of which side of the X dispute readers find persuasive. Our reading is that the episode should sharpen a distinction the industry often blurs. XRP Ledger's protocol security remains intact, and the network's fixCleanup3_3_0 upgrade, nearing activation at 82.86% validator support, continues on its own track. What failed was a single application's key management. Until third-party wallet audits become a default expectation, users on any chain should treat seed-phrase confidentiality as the non-negotiable test of a self-custody product — the moment a key leaves the device, custody has effectively been surrendered.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.