Security

XRP Healthcare shuts down after wallet flaw exposed 4,000 accounts and $450,000 drain

2 min read
Illustration of a clinic waiting-room bench with empty key hooks and scattered keys, symbolizing a wallet key compromise

XRP Healthcare shuts down after wallet flaw exposed 4,000 accounts and $450,000 drain

XRP Healthcare is winding down after a flaw in its XRPH Wallet let attackers drain roughly $450,000 from 4,010 wallets on the XRP Ledger.

The company announced the operational wind-down in a post on X on Sept. 10, three years after it started building the healthcare platform. It said the Sept. 3 wallet incident added financial and operational pressure to a business already weighed down by development costs, a prolonged crypto bear market and an unsuccessful public-listing effort.

As part of the shutdown, XRP Healthcare is preparing to delist its two tokens, XRPH and XRPHAI. Individual exchanges are expected to set their own withdrawal deadlines, and none have been announced yet. Holders should watch for those dates, because after delisting the tokens will be hard to move.

The theft itself was a two-day sweep. On-chain analysis by XRPL.to traced 10,281 payments from 4,011 sender wallets between Sept. 3 and Sept. 4, with 4,010 of those wallets classified as victims and one sender used to fund the collector account. Roughly 267,664 XRP, 23.2 million XRPH and 2.43 million XRPHAI moved into that collector, worth an estimated $450,000 to $452,000 at the time.

The company’s own developer report explains how it was possible. The wallet passed a 55-character value into xrpl.Wallet.fromEntropy(), which expected raw bytes, and only the first 16 characters survived. That left 14 variable digits and cut the number of possible keys from the intended 2^128 to about 72.9 trillion combinations. The report also flags the use of Math.random(), which could have narrowed the practical search space further. The team said it reproduced private keys for nine live wallets, including four confirmed drained accounts, using public information alone, and concluded the defect explains the drain without any access to user devices or the XRP Ledger protocol itself.

XRP Healthcare has advised anyone who used XRPH Wallet to abandon credentials generated through it and move any remaining assets with newly created keys. The wallet apps remain offline while the company keeps its intellectual property and trademark portfolio.

On Sept. 6, the company said the stolen funds had been traced end-to-end to an Ethereum address holding about 445,198 DAI, and asked victims to flag that address on Etherscan with their transaction evidence. It says it will keep working with exchanges, platforms and authorities while preserving the technical and transaction records of the incident.

Avatar of Theo Okafor

Theo Okafor

Theo Okafor reports on crypto policy and protocol governance for NFT Signals, following legislation through Congress and core development through the upgrade process.