Crypto news report · source clearly identified

XRP Healthcare shuts down after wallet flaw exposed thousands of accounts and caused $450,000 loss

Forensics traced 10,281 payments from 4,011 sender wallets, but the attacker’s exact route remains unproven and users need entirely new seeds.

XRP Healthcare, a healthcare platform built on the XRP Ledger (XRPL), announced it will wind down operations after a wallet vulnerability exposed thousands of user accounts and resulted in an estimated loss of $450,000.

Incident timeline and impact

The breach, referred to as the “XRPH Wallet incident,” occurred on September 3. Analytics by XRPL.to identified 10,281 payments originating from 4,011 sender wallets between September 3 and 4. Of those, 4,010 wallets were classified as victims after determining that a single sender funded a collector account.

Approximately 267,664 XRP, 23.2 million XRPH and 2.43 million XRPHAI were transferred to the collector, valuing the stolen assets at roughly $450,000‑$452,000.

Technical cause of the breach

Developers traced the flaw to the way XRPH Wallet generated credentials. The application passed a 55‑character string into xrpl.Wallet.fromEntropy(), which expects raw bytes. Only the first 16 characters were used, reducing the effective keyspace to about 72.9 trillion combinations (≈2^46) instead of the intended 2^128. The use of Math.random() further narrowed the practical search space.

Using public information and a partial scan of the reduced keyspace, the team reproduced private keys for nine live wallets, including four that had been drained. The defect explains the September 3 drain without requiring access to user devices or the XRPL protocol.

Response and shutdown plan

XRP Healthcare will delist its tokens (XRPH and XRPHAI) and expects exchanges to set withdrawal deadlines. The XRPH Wallet applications will remain offline while the company retains its intellectual property and trademark portfolio.

Affected users are advised to abandon any credentials generated through XRPH Wallet and move remaining assets using newly created keys. Recovery efforts will continue, and the stolen assets have been traced to an Ethereum address holding about 445,198 DAI. Users are asked to submit factual reports on Etherscan using transaction records from their drained wallets.

Future actions

The company will continue cooperating with exchanges, platforms, authorities and other parties, preserving technical and transaction records related to the incident.

Source & attribution

News Source

Publisher
CryptoSlate
Original date
September 11, 2026, 12:00 AM
Original headline
This XRP project is shutting down after wallet flaw exposed 4,000 accounts and drained $450,000
View original report ↗