EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

XRP Healthcare is winding down business after approximately $450,000 in wallet was stolen

2026-09-11 15:19:18
Bookmark

XRP Healthcare announced that it would phase out operations due to the theft of funds due to a wallet vulnerability.

According to developer incident reports and related reports, XRP Healthcare is gradually shutting down operations. Previously, due to security flaws in XRP Healthcare wallets, funds from approximately 4,010 wallets were stolen, resulting in a loss of approximately US$450,000. The project has confirmed that its digital services are temporarily unavailable while security and recovery efforts continue.



Core Points

  • XRP Healthcare is phasing out operations.
  • Wallet vulnerability caused funds to be stolen from thousands of accounts.
  • About $450,000 was stolen from about 4,010 wallets.

Overview of wallet vulnerability incidents

XRP Healthcare's official website stated that its digital services will be temporarily suspended until the security and recovery work of the XRPH wallet incident is completed. The notice confirms a service suspension rather than a permanent shutdown. According to reports, the company announced a business reduction on September 10, 2026, citing reasons including wallet incidents, development costs, a prolonged bear market and failed public listing efforts. The report pointed out that this loophole is only one of many factors, not the only reason.

According to CryptoSlate, the business reduction includes the planned delisting of XRPH and XRPHAI tokens, exchange-specific withdrawal deadlines, continued suspension of wallet applications, and continued recovery efforts. This is a project-level incident that does not involve Ripple, the broader XRP Ledger (XRPL) or other unrelated XRP services. Other companies have also suspended products before, such as Bitwise, which shut down its Dogecoin ETF less than a year after launching it.



On the meaning of "phasing out operations"

At the time of writing, the official homepage only confirmed the temporary suspension of digital services. The so-called "permanent suspension of operations" is based on support from relevant reports rather than directly obtained company statements. Therefore, a distinction should be made between "gradually stopping operations" and "all operations have been completely stopped."



About US$450,000 was stolen, involving approximately 4,010 wallets.

The developer report stated that the incident occurred on September 3, 2026, and the report itself was released on September 7, 2026. According to developers 'estimates, approximately $450,000 was transferred. This figure is a developer's estimate of the loss rather than an independently recalculated market valuation.



Estimated loss reported: approximately US$450,000

XRP Healthcare developers report estimates that approximately US$450,000 was diverted during the September 3, 2026 incident. The valuation has not been independently recalculated; the report was prepared by the developer and is not an independent audit report.



Reported losses and number of wallets affected

CryptoSlate cited analysis data from XRPL.to that a total of 10,281 payments from 4,011 sender wallets flowed to a collection address on September 3 and 4. XRPL.to identified 4,010 of them as victims after excluding one sender who provided funds for a collection address. This explains the difference between "4,011 wallets cleared" and "4,010 victims" in developer reports. These data remain attributable secondary statistics rather than independently checked ledger evidence; and 4,010 refers to the number of wallets, not the number of verified individual users.



Fact finding about wallet vulnerabilities

Developers reported that a 55-character string was passed into the `xrpl.Wallet.fromEntropy()` function, which expected to receive byte data. The truncation operation retains 16 characters (including two fixed spaces), leaving only 14 variable digits. The report gives 72,899,838,000,090 combinations of resulting keyspaces, which is approximately $2^{46.05}$, while the original expectation should be $2^{128}$.



Number of wallet key combinations reported: 72,899,838,000,090

Developers report that the defective XRPH wallet key space is approximately $2^{46.05}$combinations, compared with the original expectation of $2^{128}$. The discovery involved key generation issues for the application, and the report emphasized that XRP Ledger itself was not compromised. These findings have not been independently reproduced here.

The team said that during a partial scan of approximately 35 billion candidate inputs, they regenerated nine active wallets, including four identified victim wallets as stolen. They traced the flaw back to the submission of f1884a6 on June 13, 2023, set the public source code release date as September 10, 2023, and pointed out that the flaw had always existed in the submission before the incident on July 28, 2026.

This is a report written by the developer and is not an independent or third-party audit.
--The XRP Healthcare development team

report concluded that all wallets generated by the application must be considered compromised and users need to generate new keys. The report blamed the failure on application key generation and reiterated that XRP Ledger itself was not compromised. According to an unconfirmed company statement relayed by CryptoSlate, the stolen assets were traced to an Ethereum address holding approximately 445,198 DAI; but the underlying transaction link was not independently verified. In addition, wallet-level security issues have also attracted attention in other places, such as hacker bounty requirements in Liquid network vulnerabilities and incidents such as the separation of the MetaMask program from Consensus.



Unanswered questions for affected wallet holders

Existing evidence does not yet clarify whether compensation will be provided, how much stolen funds can be recovered, or how holders will access the remaining funds. At present, the specific shutdown schedule and verification instructions for the holder have not been confirmed in the materials.

These are gaps in the fetched evidence rather than proof of the project's silence; the company has issued a public statement and its website confirms that recovery work is in progress. Affected holders should pay close attention to the specific exchange withdrawal deadlines and delisting dates mentioned by CryptoSlate that accompany business reduction.

Disclaimer : This article is for reference only and does not constitute financial or investment advice. There are significant risks in the cryptocurrency and digital asset markets. Be sure to conduct independent research before making a decision.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP