XRP Healthcare, a healthcare-focused blockchain project built on the XRP Ledger, said it is investigating unauthorized transactions that it reports affected approximately 4,011 XRPH Wallets and removed roughly $452,000 in digital assets.
In posts on X on September 4, the company said it had traced the stolen funds and was working with exchanges and other parties about possible freezing or recovery. It also said recovery of the funds was not guaranteed. The same day it advised users not to use XRPH Wallet until further notice.
XRP Healthcare’s 4 September update described multiple unauthorized transactions involving XRPH, XRPHAI and other assets. A September 6 post published a public on-chain trail.
Stolen assets traced on-chain
XRP Healthcare said the unauthorized activity began on 3 September 2026. After an initial review it put the affected-wallet count at about 4,011 and the loss at about $452,000.
On September 6 it published this trail: from the XRP Ledger to NEAR Intents, then to Ethereum, then through Uniswap V4 into DAI.
Addresses it listed:
- XRPL collection wallet: rGGXaBdSRUfdarKDkt2csxL67F8MEGxHVB
- Final Ethereum address: 0x3DC7BFf29Fc5a051aAB250516BaBD74ae7068930
It said about 445,198 DAI remained in that Ethereum address and had not moved. Independent ledger reviews published the same destination balance. Etherscan records for that address show incoming ETH from 0x2Cf…2680 in transactions 0xc18…dd3c and 0x421…0b25, followed by an ETH-to-DAI swap in 0x67e…9b05.
Independent on-chain reporting by Handy Andy, Founder of Xspence, and a separate public forensic write-up by XRPL.to, said affected wallets lost approximately 267,664 XRP and about 23.2 million XRPH tokens before the conversion into DAI.
Those figures are ledger-derived; XRP Healthcare’s $452,000 figure is the company’s own valuation of the same incident. XRP Healthcare said it was asking platforms on the funds’ path to flag the destination address. As of its September 6–7 posts, it had not confirmed that any exchange or agency had frozen the DAI.
How access was obtained remains under investigation
The movement of the stolen assets has been traced and published. The precise method used to authorize the XRPL drains has not been established in a completed company forensic report.
XRPL.to said in its public forensic article that it decompiled XRPH Wallet Android build 8.0.15 and found a staking-related path that posted the user’s seed to a company-controlled server. XRP Healthcare said on X that management had been told the wallet was non-custodial, was not aware that the staking flow transmitted seeds to the backend, and learned of that code path from XRPL.to’s decompilation. In those posts it said it is demanding a full documented explanation from the developers who built the wallet.
XRP Healthcare has not released source code, server logs, or a finished independent audit that proves seed exposure was the cause for every drained account. Public forensics have also noted that some drained wallets showed no staking history, so that explanation does not yet cover the full set. Those points remain unresolved.
A seed phrase controls the keys to a wallet. If a seed has been copied, changing or reinstalling the app does not by itself revoke that access. XRP Healthcare initially told users to stop using XRPH Wallet while the investigation continued.
XRP Ledger not identified as the fault
XRP Healthcare has said its investigation found no evidence the XRP Ledger itself was responsible for the breach. That statement redirects attention to the wallet application and related infrastructure rather than the base protocol.
The incident has prompted public debate about how mobile wallets treat recovery material when staking or backend features are present. That debate is separate from the still-open question of exactly how the 4,011 drains were authorized.
Earlier criticisms restated after the incident
After the drains became public, several people formerly associated with Ripple and the broader XRP Ledger ecosystem repeated earlier objections to the project.
On X, user BiasGoose, a former Ripple developer-growth staffer, said he had rejected an earlier grant application from the project. He said the application showed “obvious red flags” and alleged that partnerships had been misrepresented. After the September drains he said the outcome was “not news” to him. Those grant-review and partnership claims are his account; public XRPL Grants records confirming that review were not available.
User Hazard Cookie, a former Ripple-linked developer, said earlier reviewers had identified risks that were not widely visible at the time. Coverage has described him as. Matt Hamilton, a former Ripple director of developer relations who left the company in 2022, wrote that it was “all red flags” when he spoke to the team previously as XRPayNet.
Those statements are social-media claims by the three individuals. XRP Healthcare replied on X, rejected the characterizations, and said the stolen funds were traced to a public Ethereum address that it is asking others to flag. Publicly available grant files and audit documents cited in coverage have not independently substantiated the partnership-misrepresentation allegation. The company has treated those comments as separate from the technical inquiry into the drains.
Recovery remains uncertain
XRP Healthcare has not announced a reimbursement program or a recovery deadline. It has published the destination address and said a fuller developer report is coming.
Users who believe a seed may have been exposed face a different problem from an app update: generating a new wallet with a new seed is not the same as reusing the old seed. The company has not published a user-by-user recovery process.
The DAI attributed to the conversion remained in 0x3DC…8930 in the traces published through September 6, 2026. Whether those funds can be recovered, and how the wallets were accessed, are still open.
The Crypto Times has reached out to XRP Healthcare for comments at 11:10 AM UTC.
Also Read: Crypto Hacks Cross $322M in September’s First Week as Liquid Network Alone Loses $320M
