XRP Healthcare Wallet Hack Brings Old Security Warnings Back
A seed phrase vulnerability in XRP Healthcare's staking feature drained roughly 267,000 XRP from around 4,000 wallets on September 3, 2026. Former Ripple developers say the red flags were visible long before the attack.
XRP Healthcare, a healthcare-focused project on the XRP Ledger formerly known as XRPayNet, suffered a major breach on September 3, 2026, when attackers emptied around 4,000 user wallets in approximately three hours, making off with roughly 267,000 $XRP alongside millions of XRPH and XRPHAI tokens. A portion of the stolen assets was rapidly moved to the Ethereum network, a shift that complicates recovery once funds leave their native chain.
A Flaw Hidden Inside the Staking Feature
According to forensic findings, the root cause traces to a flaw in the XRPH Wallet's staking feature. When a user activated staking, the wallet transmitted that user's private seed phrase to a remote server instead of keeping it stored locally and encrypted, as standard non-custodial wallet design requires. Anyone who had ever turned on staking effectively handed their recovery phrase to whoever controlled that server, and attackers appear to have taken advantage of exactly that opening.
Crucially, nothing in the investigation so far points to a flaw in the XRP Ledger protocol itself: the failure sits within the wallet application's architecture, not the ledger's consensus or node infrastructure.
XRP Healthcare confirmed the incident and warned users to stop using the wallet until further notice, while its team traces affected transactions on-chain and works with unspecified "relevant parties" on the possible freezing and recovery of stolen assets. The project has since identified a final Ethereum address holding approximately 445,198 DAI as the resting point for the traced funds, and says it has remained unmoved since receiving them. Affected users have been directed to report the address on Etherscan using evidence of their losses.
Former Ripple Developers Say Warning Signs Were There
Developer BiasGoose was among the first to comment publicly, saying the drain was not news to him and that he had previously rejected grant applications from the team. In his view, the project had displayed red flags from the outset, including what he described as blatant misstatements about partnerships in its funding applications. As it turned out, former Ripple employees had blacklisted the project long ago. Matt Hamilton (@HammerToe) also weighed in, saying the project "was all red flags" when he spoke to them under their previous name, XRPayNet.
In response to the criticism, the XRP Healthcare team accused the former Ripple developers of unethical behavior, saying that they had put their own names and money at stake while their opponents merely mocked the risks taken by others.
The event has reignited a broader security debate across the XRP ecosystem, with developers and users questioning how self-custody applications built on the XRP Ledger handle the most sensitive credential a user owns: the seed phrase.
Sources
COINOTAG: XRP Healthcare Wallet Hack Drains 267,000 XRP From 4,000 Wallets
U.Today: Former Ripple Devs Reveal Critical Red Flags as 4,000 XRP Ledger Wallets Are Affected
Coin-Turk: XRPL Hack Drains 267,000 XRP, Sparks Public Clash Between Project and Ripple Devs
Latest News
Read More...
Author
Soumen DattaSoumen has been a crypto researcher since 2020 and holds a master’s in Physics. His writing and research has been published by publications such as CryptoSlate and DailyCoin, as well as BSCN. His areas of focus include Bitcoin, DeFi, and high-potential altcoins like Ethereum, Solana, XRP, and Chainlink. He combines analytical depth with journalistic clarity to deliver insights for both newcomers and seasoned crypto readers.













