Loading prices…
🩸BEARISH

XRPH Wallet Bug Drains $450K, Shutters XRP Healthcare

The dollar number is modest by crypto-hack standards, but the post-mortem is the real story: a 55-character credential collapsed to 14 variable digits, putting the entire keyspace within brute-force…

XRP Healthcare is winding down operations after a wallet flaw exposed roughly 4,000 XRPL accounts and drained about $450,000 in user funds between September 3 and 4. The Sept. 3 XRPH Wallet incident, traced across 10,281 payments from 4,011 sender wallets, moved 267,664 XRP, 23.2 million XRPH and 2.43 million XRPHAI into a single collector address. XRP Healthcare said the breach added financial and operational pressure to a business already weighed down by development costs, a prolonged crypto winter and a failed public-listing effort. The platform is preparing to delist both XRPH and XRPHAI, with exchanges expected to set withdrawal deadlines.

Why it matters

The technical post-mortem explains how a small project became a case study in catastrophic keyspace collapse. XRP Healthcare's developer investigation found that XRPH Wallet passed a 55-character value into xrpl.Wallet.fromEntropy(), which expected raw bytes. Only the first 16 characters were retained, leaving just 14 variable digits and reducing the effective input space to roughly 72.9 trillion combinations, or about 2^46, compared to the intended 2^128. The use of Math.random() likely narrowed the practical search space further. The team reproduced private keys for nine live wallets, including four confirmed drained accounts, using only public information and a partial scan of the reduced keyspace.

Market impact

The weakness means exposed users cannot recover by importing the same seed into different software; new credentials are required. XRP Healthcare has asked affected users to abandon old keys and move any remaining assets via freshly generated wallets. Recovery efforts continue despite the shutdown: stolen assets were traced end-to-end to an Ethereum address holding about 445,198 DAI, and the company is asking victims to file factual reports on Etherscan with transaction records from drained wallets. The collapse is small in absolute dollar terms but reinforces a pattern of wallet-infrastructure failures dragging down otherwise functional projects, a risk the rest of the XRPL builder community will need to absorb.

Related tokens
$XRP $XRPH $XRPHAI $DAI

Frequently asked questions

  1. What happened to XRP Healthcare?

    XRP Healthcare is winding down operations after a wallet flaw in its XRPH Wallet exposed roughly 4,000 XRPL accounts and drained about $450,000 in user funds between September 3 and 4.

  2. How did the XRPH Wallet flaw work?

    The wallet passed a 55-character string into xrpl.Wallet.fromEntropy(), which expected raw bytes. Only the first 16 characters were retained, reducing the keyspace from the intended 2^128 to about 2^46, or roughly 72.9 trillion combinations.

  3. How much was stolen in the XRPH Wallet hack?

    Roughly $450,000 across 267,664 XRP, 23.2 million XRPH and 2.43 million XRPHAI, traced across 10,281 payments from 4,011 sender wallets to a single collector address.

  4. Can XRPH Wallet users recover their funds?

    No. The flaw means exposed users cannot secure a wallet by re-importing the same seed into different software. XRP Healthcare is advising affected users to abandon old credentials and create new wallets for any remaining assets.

  5. What is XRP Healthcare doing about the breach?

    The company is tracing stolen assets, which have been linked to an Ethereum address holding about 445,198 DAI. XRP Healthcare is asking victims to file factual reports on Etherscan and is preparing to delist XRPH and XRPHAI as the platform winds down.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 57m ago
Open original →