XRP Healthcare, an XRPL-based healthcare platform, is winding down operations after a wallet vulnerability exposed thousands of accounts and caused losses of approximately $450,000.
On Sept. 10, the project said the Sept. 3 XRPH Wallet incident had intensified the financial and operational strain on a business already facing high development costs, a prolonged cryptocurrency bear market and an unsuccessful attempt to secure a public listing.
The platform said it was preparing to delist its tokens, including XRPH and XRPHAI, with individual exchanges expected to establish their own withdrawal deadlines. The XRPH Wallet applications will remain offline, while the company retains its intellectual property and global trademark portfolio.
The shutdown follows a mass sweep that XRPL.to traced through 10,281 payments from 4,011 sender wallets between Sept. 3 and Sept. 4. The analytics service identified 4,010 wallets as victims after determining that a single sender had funded the collector account.
Approximately 267,664 XRP, 23.2 million XRPH and 2.43 million XRPHAI were transferred to the identified collector, bringing the estimated value of the stolen assets to between $450,000 and $452,000.
Wallet flaw severely reduced the protection around user funds
XRP Healthcare’s developers traced the breach to the way XRPH Wallet generated credentials.
According to the report, the application passed a 55-character value into xrpl.Wallet.fromEntropy(), which was designed to receive raw bytes. Only the first 16 characters were effectively retained, leaving 14 variable digits and reducing the possible input space to approximately 72.9 trillion combinations, or roughly 2^46, instead of the intended 2^128.
The developers also found that the application used Math.random(), which may have reduced the practical search space even further.
Using publicly available information and a partial scan of the weakened keyspace, the team reproduced private keys for nine active wallets, including four confirmed drained accounts. It concluded that the flaw could account for the Sept. 3 theft without requiring access to users’ devices or a vulnerability in the XRP Ledger protocol.
The weakness also means affected users cannot secure an exposed wallet merely by importing the same seed phrase into different software. XRP Healthcare has advised them to abandon credentials generated by XRPH Wallet and transfer any remaining assets with newly created keys.
Recovery efforts will continue despite the operational wind-down.
The company said the stolen assets had been traced through to an Ethereum address holding approximately 445,198 DAI. It asked affected users to submit factual reports on Etherscan using transaction records from their drained wallets.
XRP Healthcare said it would continue working with exchanges, platforms, authorities and other relevant parties while preserving technical and transaction records connected to the incident.


