The XRP Healthcare ecosystem is dealing with a major security incident after thousands of wallets connected to its mobile application were drained on September 3. XRP Healthcare confirmed that unauthorized transactions affected XRPH Wallet users and involved XRPH, XRPHAI and other assets. The company subsequently instructed users to stop using the wallet while its development team investigates how the compromise occurred.
According to an independent forensic review of the XRP Ledger activity, 4,011 wallets were emptied over roughly three hours. About 267,664 XRP was taken, alongside millions of XRPH and XRPHAI tokens. The reported value of the stolen assets was approximately $452,000, making the incident significant for a project whose wallet was promoted as a way for users to manage XRP Healthcare assets.
What Happened to the XRPH Wallets?
The attack began with a newly created address receiving funds from multiple unrelated wallets. Blockchain analysis found that the transfers occurred in rapid succession, with the attacker systematically moving balances into a common collector address. The concentration of transactions across thousands of wallets is what allowed investigators to identify the activity as a coordinated drain rather than ordinary wallet migration.
The stolen assets did not remain entirely on the XRP Ledger. Investigators traced approximately 307,000 XRP into NEAR Intents, where the assets were converted and moved across to Ethereum. The resulting funds were then swapped into approximately 445,198 DAI, which was reportedly still sitting at the Ethereum address identified in the forensic investigation.
The XRPH token suffered particularly heavy selling pressure during the incident. The forensic review reported that more than 23 million XRPH were taken from affected wallets and sold through XRP Ledger markets, while approximately 2.43 million XRPHAI were also sold. The resulting supply shock contributed to a dramatic collapse in XRPH’s market price during the attack.
Related: Ripple Engineer Says XRP Could Be “In” if Elon Musk Takes Notice
One of the most serious findings concerns the wallet’s staking functionality. The forensic investigation reported that the staking process had previously transmitted wallet seed information to a server controlled by XRP Healthcare. Nearly 1,200 wallets that had used the staking functionality were among those drained, although the investigation also found that most victims had never staked.
That distinction is important. It means the staking feature may explain part of the exposure, but it does not by itself explain the entire attack. The independent investigation found that roughly seven in ten affected wallets had not used staking, leaving a broader question about how the attacker obtained control over the remaining wallets. XRP Healthcare has said it is still investigating the root cause.
The incident therefore should not be interpreted as a failure of the XRP Ledger itself. The evidence currently points toward the XRPH Wallet application and its associated infrastructure rather than a compromise of the underlying XRP Ledger protocol. Other XRP Ledger applications and independently controlled wallets are not automatically affected simply because they operate on the same blockchain.
What the Hack Means for XRP Healthcare
For users, the immediate priority is security rather than speculation about when XRPH might recover. XRP Healthcare has explicitly told users not to use the XRPH Wallet until further notice. Anyone who believes they may have used an affected wallet should treat its credentials as potentially compromised and avoid continuing to hold funds under the same wallet credentials until the project publishes clearer guidance.
The episode also creates a difficult challenge for XRP Healthcare’s reputation. A wallet described as non-custodial carries an important expectation: users should retain control of their private keys. Any mechanism that exposes those credentials to third-party infrastructure can create a materially different security model, even if transactions themselves are normally signed on the user’s device.
The project now faces pressure to explain exactly how the breach occurred, which wallet versions were affected and whether any credentials remain exposed. A detailed post-mortem would be particularly important because users need to know whether simply avoiding the compromised application is enough or whether old wallet credentials must be permanently abandoned.
Related: Why the XRPL Could Help Build the Next Digital Economy
Recovery is another major question. The forensic investigation identified the stolen funds on Ethereum, including the reported DAI balance, while XRP Healthcare said it was working with relevant parties on possible freezing and recovery efforts. Such efforts can be difficult once assets cross multiple networks, but identifiable funds can sometimes provide investigators with useful leads for working with exchanges and other intermediaries.
For XRPH holders, the market consequences could last longer than the initial attack. A large amount of stolen tokens entering thin markets can create extreme price dislocations, while uncertainty over the wallet’s security can discourage users from interacting with the broader ecosystem. Even if the stolen funds are eventually recovered, rebuilding confidence will require more than a price rebound.
The incident is ultimately a reminder that blockchain security extends beyond the underlying network. A strong ledger does not protect users from vulnerabilities in wallet software, key-management systems or application infrastructure. XRP Healthcare now has an opportunity to demonstrate how seriously it treats that distinction by publishing a transparent investigation, removing any mechanism that exposes user seeds and subjecting a rebuilt wallet to independent security review. Until those questions are answered, caution remains the strongest position for XRPH Wallet users.















