
XRP Healthcare said 4,011 XRPH Wallet accounts were affected by unauthorized transactions beginning Sept. 3, with approximately $452,000 in XRP and related assets removed.
Summary
- XRP Healthcare said 4,011 wallets lost approximately $452,000 during unauthorized transactions beginning September 3, 2026.
- The project traced stolen assets to one Ethereum wallet and contacted exchanges about freezing funds.
- Users were told to stop using XRPH Wallet while the development team investigated the breach.
- Independent investigators attributed the compromise to seed phrases transmitted through a staking-related server request process.
- Former Ripple developers said earlier grant reviews identified project risks, allegations XRP Healthcare publicly disputed.
XRP Healthcare traces stolen funds to Ethereum
XRP Healthcare initially confirmed unauthorized transactions involving XRP, XRPH, XRPHAI and other assets. The company instructed users to stop using XRPH Wallet until further notice while its developers investigated the compromise.
A subsequent update placed the affected wallet count at approximately 4,011 and the estimated loss at $452,000. The company said investigators traced the assets to one Ethereum address and contacted exchanges and other parties about freezing or recovering them.
Independent on-chain researcher Handy Andy reported that the affected accounts lost 267,664 XRP and approximately 23.2 million XRPH tokens. The researcher said the assets were converted into roughly 445,198 DAI on Ethereum and remained in the destination wallet at the time of the update.
Investigators examine a possible seed phrase leak
Independent investigators attributed the XRPH Wallet breach to its staking function. Their analysis alleged that activating staking caused users’ seed phrases to be transmitted to a remote server.
XRP Healthcare had not published source code, server logs or an independent forensic report confirming that explanation when this article was prepared. The seed phrase exposure therefore remains a researcher finding rather than a company-confirmed root cause.
A seed phrase provides control over every private key generated by a wallet. Anyone obtaining it can reproduce the wallet and authorize transactions without accessing the victim’s phone. Crypto.news previously explained how seed phrases function as master recovery keys and why they should never leave the user’s secure environment.
The reported failure resembles a July incident in which a compromised software package transmitted private keys through a fraudulent telemetry function. However, no evidence currently connects the two cases or their perpetrators.
Former Ripple developers revive earlier concerns
The breach prompted public criticism from developers previously associated with Ripple and the XRP Ledger ecosystem. BiasGoose said he had rejected an earlier grant application from the project because the application showed what he considered clear warning signs.
He later alleged that the team had misrepresented partnerships in its application. Hazard Cookie said earlier reviewers had identified risks that were not publicly visible at the time.
Former Ripple developer Matt Hamilton also referred to the project’s earlier reputation within the community. These statements represent the developers’ accounts. Public grant records or complete audit documents substantiating every allegation were not available.
XRP Healthcare rejected the tone of the criticism and accused former developers of celebrating another team’s losses. Its response called that conduct “genuinely pathetic” and said the company had put its own reputation and capital at risk. The exchange did not resolve the technical questions surrounding the wallet.
Users need new wallets before moving remaining assets
XRP Healthcare must now establish the precise entry point, determine when seed information may have been exposed and identify which application versions were affected. A full postmortem should also explain whether the reported server retained seed phrases and who could access them.
Users who created or imported seed phrases into the affected application cannot rely solely on an app update if those phrases were exposed. Remaining funds should be transferred to newly generated wallets using trusted software. Reusing an old seed would preserve the attacker’s access.
The company has not announced a reimbursement program or recovery deadline. It also has not confirmed whether law enforcement or any exchange successfully froze the traced funds. Users should rely on official channels and reject unsolicited recovery offers requesting keys, seed phrases or payments.
The incident follows a wider rise in wallet and infrastructure compromises. As crypto.news reported, operational security failures caused 74% of stolen funds during the first half of 2026. Separately, Ripple’s recent audit program identified 96 vulnerabilities across proposed XRPL amendments, showing the value of testing before software reaches users.




