XRP Healthcare shuts down after wallet flaw drains $450K from 4,000 accounts
In brief
- XRP Healthcare announced operational shutdown following September 3 wallet breach affecting 4,011 accounts
- Roughly $450,000 in XRP, XRPH, and XRPHAI tokens were stolen and traced to an Ethereum address
- Wallet flaw reduced entropy from 2^128 to 2^46, enabling attackers to brute-force private keys
- Users must generate entirely new wallet credentials; importing the same seed provides no protection
The Breach and Token Delisting
XRP Healthcare announced on September 10 that it was preparing to delist its tokens, including XRPH and XRPHAI, with individual exchanges expected to set withdrawal deadlines. The move marks the effective end of the platform's operations, though the company said it will continue working with exchanges, platforms, authorities and other parties while preserving technical and transaction records.
XRPL.to traced 10,281 payments from 4,011 sender wallets between September 3 and 4, with 4,010 of those wallets classified as victims. About 267,664 XRP, 23.2 million XRPH and 2.43 million XRPHAI were moved into the identified collector, putting the value of stolen assets at roughly $450,000 to $452,000.
How the Wallet Flaw Worked
XRP Healthcare's developer investigation traced the breach to how the XRPH Wallet generated credentials. The application passed a 55-character value into xrpl.Wallet.fromEntropy() which expected raw bytes. Only the first 16 characters were effectively retained, leaving 14 variable digits and reducing the possible input space to about 72.9 trillion combinations, or roughly 2^46, from the intended 2^128.
The developers also found use of Math.random(), which could have reduced the practical search space further. The team reproduced private keys for nine live wallets, including four confirmed drained accounts, using public information and a partial scan of the reduced keyspace. This defect explains the September 3 drain without requiring access to user devices or the XRP Ledger protocol itself.
What Users Must Do Now
"The weakness also means users cannot secure an exposed wallet simply by importing the same seed into different software." — XRP Healthcare developer investigation
XRP Healthcare advised affected users to abandon credentials generated through XRPH Wallet and move any remaining assets using newly created keys. The stolen assets were traced end-to-end to an Ethereum address holding about 445,198 DAI. The company asked affected users to submit factual reports on Etherscan using transaction records from their drained wallets.
Recovery efforts will continue despite the operational wind-down. The XRPH Wallet applications will remain offline while the company retains its intellectual property and global trademark portfolio.
Frequently asked questions
What caused the XRP Healthcare wallet breach?
The XRPH Wallet application passed a 55-character value into xrpl.Wallet.fromEntropy() which expected raw bytes. Only the first 16 characters were retained, reducing the entropy from 2^128 to 2^46. The use of Math.random() further weakened the keyspace, allowing attackers to brute-force private keys.
Can users recover security by importing their seed into another wallet?
No. The fundamental weakness means users cannot secure an exposed wallet simply by importing the same seed into different software. Users must generate entirely new wallet credentials and move any remaining assets using newly created keys.
How much was stolen and where did it go?
Approximately $450,000 to $452,000 worth of XRP, XRPH, and XRPHAI tokens were stolen from 4,010 victim wallets. The stolen assets were traced end-to-end to an Ethereum address holding about 445,198 DAI.


