
XRP Healthcare Reports Breach Affecting 4,011 Wallets
XRP Healthcare says that 4,011 XRPH Wallet accounts were affected by unauthorized transactions beginning Sept. 3, with approximately $452,000 in XRP and related assets removed. The details were reported on Sept. 7, 2026, at 9:10 AM UTC.
The project initially said it was investigating unauthorized transactions involving XRP, XRPH, XRPHAI and other assets. XRP Healthcare instructed users to stop using XRPH Wallet until further notice while its developers investigated the compromise. In a subsequent update, the company placed the affected wallet count at approximately 4,011 and the estimated loss at $452,000.
Stolen Funds Traced to One Ethereum Address
The company said investigators traced the stolen assets to one Ethereum address and contacted exchanges and other parties about freezing or recovering them. Independent on-chain researcher Handy Andy reported that the affected accounts lost 267,664 XRP and approximately 23.2 million XRPH tokens. He added that the assets were converted into roughly 445,198 DAI on Ethereum and remained in the destination wallet at the time of the update.
Investigators Probe Possible Seed Phrase Leak
Independent investigators attributed the XRPH Wallet breach to its staking function. Their analysis alleged that activating staking caused users’ seed phrases to be transmitted to a remote server. XRP Healthcare had not published source code, server logs or an independent forensic report confirming that explanation at the time of writing, so the seed phrase exposure remains a researcher finding rather than a company-confirmed root cause.
A seed phrase provides control over every private key generated by a wallet. Anyone who obtains it can reproduce the wallet and authorize transactions without accessing the victim’s phone. Crypto.news has previously explained how seed phrases work and why they should never leave the user’s secure environment.
The reported failure resembles a July incident in which an app was compromised through a fraudulent telemetry function, although no evidence currently connects the two cases or their perpetrators.
Former Ripple Developers Raise Earlier Concerns
The breach prompted public criticism from developers previously associated with Ripple and the XRP Ledger ecosystem. Developer BiasGoose said he had rejected an earlier grant application from the project because it showed what he considered clear warning signs. He later said the team had misrepresented partnerships in its application. Developer Hazard Cookie said earlier reviewers had identified risks that were not publicly visible at the time. Former Ripple developer Matt Hamilton also commented on the project’s earlier reputation within the community.
“Yup was all red flags when I spoke to them before as XRPayNet.” — Matt Hamilton
These statements represent the developers’ accounts. Public grant records or complete audit documents substantiating every allegation were not available.
Company Response and Unresolved Questions
XRP Healthcare rejected the tone of the criticism and accused former developers of celebrating another team’s losses. In its statement, the company called that conduct “genuinely pathetic” and said it had put its own reputation and capital at risk. The response did not resolve the technical questions surrounding the wallet.
Users Need New Wallets Before Moving Remaining Assets
XRP Healthcare must now establish the precise entry point, determine when seed information may have been exposed and identify which application versions were affected. A full postmortem should also explain whether the reported server retained seed phrases and who could access them.
- Users who created or imported seed phrases into the affected application cannot rely solely on an app update if those phrases were exposed.
- Remaining funds should be transferred to newly generated wallets created with trusted software.
- Reusing an old seed would preserve the attacker’s access.
The company has not announced a reimbursement program or recovery deadline. It also has not confirmed whether law enforcement or any exchange successfully froze the traced funds. Users should rely on official channels and reject unsolicited recovery offers requesting keys, seed phrases or payments.
The incident follows a wider rise in wallet and infrastructure compromises reported during the first half of 2026. Separately, Ripple’s recent audit program highlighted the value of testing software before it reaches users.




