Highlights

  • Attackers drained about 267,000 XRP plus millions in related tokens from XRP Healthcare's mobile wallet app on Sept. 3, hitting roughly 4,000 wallets in about three hours.
  • The breach traced to the app's staking feature, which transmitted users' private seed phrases to a remote server instead of keeping them on-device.
  • The XRP Ledger's core protocol itself was untouched — the vulnerability lived entirely in XRP Healthcare's wallet software.
  • Stolen funds were quickly bridged off the XRP Ledger, with reports citing NEAR Intents as one route used to move assets toward Ethereum.
  • The hack triggered a public feud after former Ripple developers said they had flagged XRP Healthcare as a red flag for years.

A Fast, Coordinated Drain

XRP Healthcare, a blockchain-based health initiative formerly known as XRPayNet, confirmed on September 3 that attackers drained roughly 267,000 XRP — worth close to $200,000 at the time — along with millions of dollars in its native XRPH and XRPHAI tokens from users' mobile wallets. The breach hit an estimated 4,000 wallets within about three hours, according to on-chain trackers who flagged the exploit in real time. The project confirmed the theft publicly, said its developers were conducting an urgent investigation, and stated it was tracing the stolen funds on-chain while coordinating with authorities in an attempt to freeze and recover user assets.

How the Wallet Was Breached

The root cause traces to XRP Healthcare's own mobile app rather than the XRP Ledger itself. When users enabled the app's staking feature, their wallet's private seed phrase was transmitted to a remote server instead of staying on-device — the single point of failure that let attackers drain roughly 4,000 wallets in one coordinated sweep. Security researchers who reviewed the incident stressed that the XRP Ledger's consensus protocol was never compromised; ordinary non-custodial XRP wallets and XRP held through spot ETFs were unaffected, and the exposure was isolated entirely to XRP Healthcare's proprietary wallet software.

Once drained, the funds moved quickly off the XRP Ledger. Reports of the attack cited NEAR Intents, a cross-chain bridging protocol, as one of the routes used to move the stolen assets toward Ethereum — a common next step for attackers, since spreading funds across chains and swap venues makes on-chain tracing and recovery considerably harder. XRP Healthcare said it was working with exchanges and investigators to flag and freeze the stolen tokens before they could be fully cashed out, though funds that have already crossed to another chain are historically much harder to claw back.

A Public Feud Erupts

The hack quickly became less about the stolen sum — modest by the standards of this year's larger exploits — and more about who XRP Healthcare is. Within hours, several former Ripple developers, including BiasGoose and Matt Hamilton, said publicly that they had rejected the project's grant applications years earlier over what BiasGoose described as a pattern of "blatantly lying about partnerships" and unnecessary tokenization. BiasGoose said the breach was "not news to me," pointing to concerns the developer community had raised as far back as the 2022-2024 market cycle. XRP Healthcare's team pushed back, saying it "expected far more character from industry veterans" than public mockery during an active recovery effort, while BiasGoose countered that he had "never taken risks with other people's money."

Related: BounceBit Abandons Its Own Blockchain After $3M Exploit

For the broader XRP ecosystem, the episode is a reminder that ledger-level security and application-level security are two different things — a distinction that matters as more consumer-facing apps build on XRPL, alongside infrastructure pushes like RLUSD's stablecoin supply topping $1 billion on the ledger. It also lands at a moment when XRP exchange withdrawals are already running at their highest level since 2019, reflecting a broader push by holders toward self-custody that this kind of third-party wallet exploit directly complicates.

What Comes Next

XRP Healthcare says its investigation is ongoing, with the team continuing to trace the stolen tokens on-chain and coordinate with exchanges and law enforcement to flag wallets tied to the attacker before the funds are fully laundered. The practical test in the coming weeks is whether any of the roughly $200,000-plus in stolen assets gets frozen or clawed back once they surface on centralized exchanges, since intents-based bridges and cross-chain swaps only complicate tracing rather than making funds untraceable outright. For users, the more immediate fallout is whether XRP Healthcare can rebuild trust in its wallet app at all — the public spat with former Ripple developers has already put the project's broader credibility, not just its security architecture, under scrutiny.

FAQ

What caused the XRP Healthcare wallet hack?
The app's staking feature transmitted users' private seed phrases to a remote server instead of keeping them on-device, giving attackers a single point of failure to drain roughly 4,000 wallets.

Was the XRP Ledger itself hacked?
No. The XRP Ledger's core protocol was untouched; the vulnerability was isolated to XRP Healthcare's own mobile wallet software, so ordinary non-custodial XRP wallets and XRP ETFs were unaffected.

How much was stolen in the hack?
Attackers drained about 267,000 XRP plus millions of dollars in XRP Healthcare's XRPH and XRPHAI tokens from roughly 4,000 wallets within about three hours on Sept. 3.

Why are former Ripple developers involved in the dispute?
Developers including BiasGoose and Matt Hamilton said they had flagged XRP Healthcare's practices as red flags in prior years, sparking a public feud with the project's team after the hack.