4,011 XRP Wallets Drained as 267,664 XRP Is Stolen

Bybit
Bitbuy


XRP Healthcare has taken its XRPH Wallet app offline after a breach drained 4,011 user wallets in roughly three hours, including 267,664 XRP.

The incident is notable not because the XRP Ledger itself failed, but because the compromise appears to have occurred at the wallet application layer.

According to XRP Ledger analytics platform XRPL.to, the affected wallets also lost 23.2 million XRPH and 2.43 million XRPHAI. XRP Healthcare has estimated the stolen assets at roughly $452,000.

4,011 Wallets Were Swept in Three Hours

The attack began late Sept. 3.

itrust

XRPL.to found that a newly created address received the balances of 4,011 wallets, with the largest accounts drained first. By 22:30 UTC, the collection wallet already held more than 242,000 XRP.

The stolen funds were then moved across chains.

XRPL.to traced 311,613 XRP through NEAR Intents, where it was converted into about 178.46 ETH and ultimately into 445,198 DAI on Ethereum. That DAI remained unmoved in a single address at the time of the forensic report.

XRPH Wallet access has since been disabled while the incident is investigated. Importantly, taking the app offline does not remove users’ XRPL accounts: balances and transaction history remain visible directly on-chain.

Stolen XRPH Wallet funds were rapidly moved to Ethereum.Stolen XRPH Wallet funds were rapidly moved to Ethereum.Stolen XRPH Wallet funds were rapidly moved to Ethereum.
Stolen XRPH Wallet funds were rapidly moved to Ethereum.

The Bigger Risk May Be How Wallet Keys Were Handled

The more important angle is how broad the exposure appears to have been.

XRPL.to reported that the XRPH app stored wallet seeds unencrypted on the phone, while its staking feature sent users’ seed information to XRP Healthcare’s server.

Of 1,225 wallets that had used staking, 1,198 were drained.

But roughly seven in ten victims had never staked at all, suggesting the vulnerability may not have been limited to that feature.

That distinction matters because the XRP Ledger itself has shown no evidence of a protocol compromise.

A similar separation emerged after the recent Coreum-XRPL bridge exploit, when nearly 200,000 XRP was drained through flawed relayer logic even though XRPL validator keys remained secure.

The latest breach therefore reinforces a broader point: a blockchain can remain operational while the apps, bridges and wallets sitting on top of it create separate attack surfaces.

XRP Users Face Growing Wallet-Level Risks

The incident also comes amid a series of security warnings aimed at XRP holders.

The XRP Ledger Foundation recently warned users about fake XRP rewards campaigns designed to steal wallet credentials.

Meanwhile, interest in self-custody has grown as more XRP moves away from exchanges, making secure key management increasingly important.

Our hardware wallet comparison highlights why keeping private keys isolated from online services can reduce certain attack risks.

XRPL itself has continued rolling out network safeguards, including the recent 3.2.1 security update.



Source link

Paxful

Be the first to comment

Leave a Reply

Your email address will not be published.


*