XRP Healthcare says unauthorized transactions beginning on Sept. 3 affected 4,011 XRPH Wallet accounts, removing about $452,000 in XRP and related assets. The project said it traced the stolen funds to a single Ethereum wallet and contacted exchanges in an effort to freeze the assets.

The incident has drawn wider scrutiny because independent researchers say the breach may have stemmed from the wallet’s staking function. At publication, however, XRP Healthcare had not released source code, server logs or an external forensic report confirming that explanation, leaving the reported seed phrase exposure as an unverified researcher finding rather than an established company conclusion.

Scale of the losses

According to XRP Healthcare, thousands of wallet users were hit as unauthorized transfers moved funds out of affected accounts. The company’s estimate put the total loss at roughly $452,000 across XRP and related assets.

Independent on-chain researcher Handy Andy said the drained assets included 267,664 XRP and about 23.2 million XRPH tokens. The researcher added that those holdings were converted into approximately 445,198 DAI on Ethereum and, at the time of the update, remained in the destination wallet identified by investigators.

Researchers focus on staking feature

Independent investigators said the likely point of compromise was the XRPH Wallet staking function. Their allegation is that when users activated staking, the application transmitted seed phrases to a remote server, potentially exposing control of the wallets.

That account had not been formally verified by XRP Healthcare when the source report was prepared. The company had not published the underlying technical evidence needed to confirm the root cause, and no independent forensic report had yet been released. Because a seed phrase controls every private key generated by a wallet, proving whether and when such data was exposed is central to explaining the breach.

Backlash inside the XRP community

The breach triggered public criticism from developers previously associated with Ripple and the XRP Ledger ecosystem. XRP Healthcare pushed back on the tone of those reactions and accused former developers of treating another team’s losses as something to celebrate.

The dispute has added a community dimension to what is already a technical and security crisis, but it does not resolve the core question of how attackers gained access to user wallets.

What remains to be established

XRP Healthcare still needs to determine the exact entry point, when any seed data may have been exposed and which versions of the application were affected. A full postmortem would also need to address whether any server retained seed phrases and who, if anyone, could access them.

For users who created or imported seed phrases into the affected wallet, an application update alone would not be enough if those phrases were compromised. The next confirmed step is a fuller technical explanation from the company or an independent forensic review, while affected users would need to move any remaining assets to newly generated wallets created with trusted software rather than continue using an old seed.

Source: crypto.news