In Brief:
- XRP Healthcare disabled its XRPH Wallet while investigating unauthorized transfers affecting 4,011 users and approximately $452,000 in stolen digital assets.
- Blockchain records show stolen XRP moved through NEAR Intents, emerged on Ethereum, and became 445,198 DAI in one unmoved address.
- Investigators are examining wallet key storage because most affected accounts never used staking, suggesting exposure extended beyond that specific feature.
XRP Healthcare has taken its XRPH Wallet application offline while investigating a security breach affecting 4,011 user wallets. According to XRP Healthcare, pproximately $452,000 in assets left affected accounts through unauthorized transfers, prompting XRP Healthcare to disable the application as a security precaution.
Users cannot access accounts through the application during the assessment, although their wallets remain active as separate XRP Ledger accounts. Users with XRPL addresses can examine balances and histories through blockchain explorers, while XRP Healthcare has urged customers to avoid the wallet.
Preliminary findings revealed no XRP Ledger fault or network security failure, but investigators are examining how private credentials became exposed.
Stolen XRP Moves Through NEAR Intents Into Ethereum
According to XRP Ledger analytics platform xrpl.to, the unauthorized transactions occurred within three hours on September 3, with a newly created address receiving balances from 4,011 wallets. The transferred assets included 267,664 XRP, 23.2 million XRPH tokens, and 2.43 million XRPHAI tokens, while 311,613 XRP entered NEAR Intents.
Those assets emerged on Ethereum as 178.46 ETH within one minute of each deposit before becoming 445,198 DAI in one identified address. Significantly, the DAI remained unmoved when investigators published their findings, leaving the funds visible through blockchain records.
Wallet Key Storage Practices Face Investigation
We're back on X.
— 36Crypto (@36Crypto1) August 21, 2026
Our previous account (36crypto2) is currently unavailable while we continue working through the appeal process. In the meantime, this is our new official account. While you are on this page, please support us by sharing and following.
According to xrpl.to, the XRPH Wallet signed payments on users’ phones and stored seed phrases without encryption. Moreover, its staking feature reportedly transmitted seed phrases to an XRP Healthcare server.
Records indicate that 1,225 wallets used the staking service, mainly between December 2023 and July 2024. Attackers drained 1,198 staking wallets alongside XRP Healthcare’s staking wallet.
However, approximately 70% of affected wallets had never used staking, indicating that exposure may extend beyond that feature. This pattern raised concerns about the application’s wider key-management system.
XRP Healthcare has not confirmed the breach method because investigators require additional technical evidence. The application will remain unavailable during the company’s security review.
Also Read: Solana Transaction Expansion Opens Door to ZK Rollups and Complex Applications
