XRP Healthcare has disclosed that an ongoing investigation into a wallet security incident has now identified 4,011 affected wallets and roughly $452,000 in unauthorized outflows.
The breach came to light on September 4, 2026, when the project issued a security update urging users to stop using the XRPH Wallet until further notice. The app was subsequently taken offline by the XRP Healthcare team as a precaution, not by an attacker. The company clarified that funds still visible on-chain remain in users' XRP Ledger accounts, but access through the app has been disabled while the compromise is investigated.
According to XRP Ledger analytics platform xrpl.to, the incident unfolded over roughly three hours on the evening of September 3, 2026. An address that had not existed an hour earlier received the entire balances of 4,011 wallets, including 267,664 XRP, 23.2 million XRPH and 2.43 million XRPHAI. A total of 311,613 XRP was then moved through NEAR Intents, emerging on Ethereum as 178.46 ETH before being converted into approximately 445,198 DAI at one address that has not moved since.
XRP Healthcare stated that its preliminary investigation found no evidence that the XRP Ledger itself was at fault. However, the exact method by which wallet keys were compromised remains under investigation. Analytics data suggested that XRPH payments are signed on the phone while the seed is stored unencrypted, and that a staking feature sends the seed to XRP Healthcare's server. Of 1,225 wallets that staked between December 2023 and July 2024, 1,198 were drained, along with XRP Healthcare's own staking wallet. Yet seven in ten victims never staked, indicating that the exposure may have affected the app's broader user base rather than a single feature.
The project said the stolen assets had been traced but recovery could not be guaranteed, and it had not announced a reimbursement program or confirmed freeze. It plans to pursue address blacklisting and other recovery options. Users have been advised to move remaining assets to newly generated wallets and to avoid unsolicited recovery messages requesting seed phrases, keys or payments.