XRP Healthcare is winding down its normal business operations, less than two weeks after a Sept. 3, 2026, security incident drained roughly $452,000 across 4,011 wallets connected to its XRPH Wallet application.
The company said in a Sept. 10, 2026, announcement that the breach compounded financial pressure from years of development costs, a prolonged bear market and a failed public-listing effort.
4,011 wallets were affected
The wallet incident began on September 3, when unauthorized transactions were detected across XRPH Wallet accounts.
XRP Healthcare previously estimated that 4,011 wallets were affected and that about $452,000 worth of digital assets were taken. Independent blockchain analysis found that the drained assets included about 267,664 XRP, 23.2 million XRPH and 2.43 million XRPHAI.
The stolen XRP was moved across networks through NEAR Intents before being converted into Ethereum-based assets.
Blockchain investigators traced approximately 445,198 DAI to a single Ethereum address, where the funds were reported to remain unmoved at the time of the latest reports.
The figures are based on XRP Healthcare’s incident estimates and independent on-chain analysis. They have not been presented as an independently audited financial loss.
XRP Healthcare identifies a wallet-generation flaw
XRP Healthcare said its development team completed a technical root-cause investigation and identified a defect in the wallet-generation process.
According to the company, the application passed improperly formatted entropy into the XRP Ledger’s key-generation function. That reduced the effective number of possible private keys and made it possible to reconstruct affected keys through offline computation.
In simple terms, the wallet was not generating private keys with enough randomness.
A cryptocurrency wallet depends on its private key to authorize transactions. If an attacker can predict or reconstruct that key, they can potentially move the assets controlled by the wallet without needing the user’s permission.
Independent researchers have also examined the wallet’s code and reached similar conclusions about weaknesses in the wallet-generation process, although some researchers have disputed the company’s account of how seed information was handled.
XRP Healthcare has specifically said its root-cause investigation did not identify seed transmission to Firebase as the cause of the drain. It said separate code analysis found that seeds remained on users’ devices.
The competing technical findings mean the precise path through which the attacker gained access to the affected wallets remains an important part of the wider investigation.
The XRP Ledger itself was not compromised
The incident does not appear to have been caused by a failure in the XRP Ledger protocol.
The blockchain continued processing transactions according to its normal rules. The problem was linked to the software used to create and manage wallets connected to the ecosystem.
A blockchain can remain secure while applications built around it contain vulnerabilities. If an attacker obtains a valid private key, the blockchain generally treats transactions signed with that key as legitimate.
In this case, blockchain records made it possible for investigators to trace the movement of the stolen assets even after they left the XRP Ledger.
XRPH and XRPHAI face delisting
The operational wind-down also means changes are coming for holders of XRP Healthcare’s tokens.XRP Healthcare said it is coordinating the orderly delisting of XRPH and XRPHAI with exchanges.
However, the company said individual exchanges will determine their own trading closure, deposit suspension and withdrawal arrangements.
That means holders will need to monitor official announcements from the exchanges where their tokens are held.
A delisting does not automatically erase tokens from private wallets. But it can reduce the number of platforms where users can trade or withdraw the assets.
XRP Healthcare has not announced a compensation programme for users who lost funds in the wallet incident.
It has instead said it will continue pursuing recovery options and working with exchanges, platforms and authorities.
What happens to XRP Healthcare now?
The company said its intellectual property and global trademark portfolio will be retained and managed separately from the operational wind-down.
It has not disclosed its full financial position, including assets, liabilities, cash reserves or outstanding obligations. It also has not provided a timetable for completing the wind-down.
For affected wallet users, the XRPH Wallet applications will remain offline.
The bigger issue now is whether any of the stolen funds can be recovered and whether XRP Healthcare’s technical findings can fully explain how thousands of wallets became vulnerable.
The company is ending its normal operations, but the consequences of the September 3rd breach are far from over.