
XRP Healthcare has officially shut down normal operations after the September 3 wallet incident that affected 4,011 accounts and resulted in approximately $452,000 in XRP and related assets stolen. According to the company's latest announcement, the wind-down covers regular business activities but does not close the response to the wallet incident. The company will continue pursuing available recovery routes for affected assets while cooperating with exchanges, online platforms, authorities and other parties involved in tracing or recovering the funds. XRP Healthcare has not published a complete list of affected addresses, transaction hashes or recovered balances, leaving outside researchers unable to fully reproduce the total loss.
XRPH Wallet suffered unauthorized transactions starting September 3, 2026, affecting 4,011 accounts and resulting in approximately $452,000 in XRP and related assets stolen. According to reports from Crypto.news, the company initially confirmed unauthorized transactions involving XRP, XRPH, XRPHAI and other assets before providing the final wallet count and estimated loss figures. The project instructed users to stop using XRPH Wallet until further notice while its developers investigated the compromise. Independent investigators attributed the compromise to seed phrases transmitted through a staking-related server request process, as reported by Crypto.news. The company traced the stolen assets to one Ethereum address and contacted exchanges and other parties about freezing or recovering them.
Independent developers cited by U.Today attributed the compromise to how the XRPH Wallet generated and handled recovery phrases, with claims focusing on application code rather than identifying a flaw in the XRP Ledger consensus protocol. One allegation stated that the wallet used insufficient randomness when creating seed phrases, allowing an attacker to search the remaining combinations offline and derive private keys. A separate claim based on decompiled application code said the software transmitted users' seed phrases over a network connection. XRP Healthcare said it learned of the alleged transmission only after the incident and had trusted the developers hired to build the application. The breach reportedly involved XRPH Wallet's staking function, where activating staking caused users' seed phrases to be transmitted to a remote server. As reported by Crypto.news, XRP Healthcare had not published source code, server logs or an independent forensic report confirming this explanation when the article was prepared.
XRP Healthcare is coordinating the removal of XRPH and XRPHAI from trading platforms through an orderly process with exchange partners. Each exchange will set its own trading closure, deposit suspension and withdrawal deadlines, leaving holders responsible for checking notices issued by the venue where their tokens remain. At the time of the wind-down statement, XRP Healthcare had not published a consolidated list of participating exchanges or deadlines. Searchable reports from Bitget and KuCoin described the closure, but exchange-specific withdrawal schedules were not clearly available in the cited notices. XRPHAI began trading on BitMart in July 2026, according to the project's launch announcement, meaning holders with tokens on BitMart must wait for or locate a notice from the exchange before relying on any withdrawal date attributed to the project.
XRP Healthcare cited financial and operational pressure after three years of spending on development, infrastructure and product delivery as reasons for shutting down. The company said continuing its regular business was 'no longer sustainable' and attributed costs to a prolonged bear market and the expense of an unsuccessful public-listing process. XRP Healthcare did not name the proposed exchange, disclose how much the listing process cost or identify the advisers involved. The company has not announced a reimbursement program or recovery deadline, nor confirmed whether law enforcement or any exchange successfully froze the traced funds. Users who created or imported seed phrases into the affected application cannot rely solely on an app update if those phrases were exposed, as reusing an old seed would preserve the attacker's access.
The breach prompted public criticism from developers previously associated with Ripple and the XRP Ledger ecosystem. According to Crypto.news, BiasGoose said he had rejected an earlier grant application from the project because the application showed what he considered clear warning signs and later alleged that the team had misrepresented partnerships. Hazard Cookie said earlier reviewers had identified risks that were not publicly visible at the time. Former Ripple developer Matt Hamilton and XRP Ledger community contributors Vet and Hazard Cookie said they had raised concerns about the project before the September incident. Vet stated that he rejected grant requests tied to the project because its documents contained what he described as inaccurate partnership claims. XRP Healthcare rejected the tone of the criticism and accused former developers of celebrating another team's losses, calling that conduct 'genuinely pathetic' and stating the company had put its own reputation and capital at risk.