XRP Healthcare to Shut Down After XRPH Wallet Bug Exposes 4,000 Accounts and Spurs $450,000 Theft

AI Market Summary
XRP Healthcare is shutting down after a wallet key-generation flaw exposed ~4,000 accounts and enabled ~$450k in theft, with tokens (XRPH, XRPHAI) set for delisting and withdrawal deadlines left to exchanges. The incident highlights application-layer security risk on XRPL rather than protocol failure, but can still weigh on XRPL ecosystem confidence and liquidity. Stolen funds were traced to an Ethereum address holding DAI, supporting ongoing investigations.
Impact level
● Medium
Affected assets
XRP/USDT-2.88%
AI Insight · XRP/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
XRP Healthcare, a healthcare platform built on the XRP Ledger (XRPL), is winding down after a vulnerability in its XRPH Wallet exposed thousands of user accounts and led to losses of about $450,000. In a Sept. 10 update, the project said the Sept. 3 XRPH Wallet incident compounded financial and operational strain amid high development costs, a prolonged crypto bear market and a failed attempt to secure a public listing. The company said it plans to delist its tokens, including XRPH and XRPHAI, with individual exchanges expected to set their own withdrawal deadlines. XRPH Wallet apps will remain offline, while the company retains its intellectual property and global trademark portfolio. Blockchain analytics firm XRPL.to traced a mass sweep across 10,281 payments involving 4,011 sender wallets between Sept. 3 and Sept. 4, classifying 4,010 wallets as victims after concluding a single sender funded the collector account. The collector received about 267,664 XRP, 23.2 million XRPH and 2.43 million XRPHAI, valuing the stolen assets at roughly $450,000 to $452,000. According to XRP Healthcare's developer investigation, the breach stemmed from how XRPH Wallet generated credentials. The app passed a 55-character value into xrpl.Wallet.fromEntropy(), which expects raw bytes. As a result, only the first 16 characters were effectively used, leaving 14 variable digits and shrinking the keyspace to about 72.9 trillion combinations (around 2^46) from the intended 2^128. Developers also flagged use of Math.random(), which may have reduced the practical search space further. The team said it was able to reproduce private keys for nine live wallets, including four confirmed drained accounts, using public information and a partial scan of the reduced keyspace. It concluded the flaw can explain the Sept. 3 theft without access to user devices or the XRPL protocol. The company also warned that importing the same seed into different wallet software does not secure an exposed wallet. XRP Healthcare advised users to abandon any credentials generated through XRPH Wallet and move remaining funds using newly created keys. It said recovery efforts will continue despite the winddown. The company reported that the stolen assets were traced end-to-end to an Ethereum address holding about 445,198 DAI, and asked affected users to submit factual reports on Etherscan using transaction records from their drained wallets. XRP Healthcare said it will keep working with exchanges, platforms, authorities and other parties, while preserving technical and transaction records tied to the incident.