A wallet coding flaw just helped shut down an entire XRP project

fiverr
Coinmama


XRP Healthcare, an healthcare platform build on the XRP Ledger (XRPL), is winding down operations after a wallet flaw exposed thousands of accounts and led to roughly $450,000 in losses.

On Sept. 10, the project said the Sept. 3 XRPH Wallet incident added financial and operational pressure to a business already burdened by development costs, a prolonged crypto bear market and an unsuccessful public-listing effort.

Due to this, the platform said it was preparing to delist its tokens, including XRPH and XRPHAI, with individual exchanges expected to set withdrawal deadlines. The XRPH Wallet applications will remain offline while the company retains its intellectual property and global trademark portfolio.

The shutdown follows a mass sweep that XRPL.to traced across 10,281 payments from 4,011 sender wallets between Sept. 3 and Sept. 4. The analytics service classified 4,010 of those wallets as victims after determining that one sender funded the collector account.

okex

Related Reading

XRP Ledger developer kit compromised with backdoor to steal wallet private keys

About 267,664 XRP, 23.2 million XRPH and 2.43 million XRPHAI were moved into the identified collector, putting the value of the stolen assets at roughly $450,000 to $452,000.

Wallet flaw collapsed the keyspace protecting user funds

XRP Healthcare’s developer investigation traced the breach to how XRPH Wallet generated credentials.

The report said the application passed a 55-character value into xrpl.Wallet.fromEntropy(), which expected raw bytes. Only the first 16 characters were effectively retained, leaving 14 variable digits and reducing the possible input space to about 72.9 trillion combinations, or roughly 2^46, from the intended 2^128.