Smartphone displaying the XRP logo in front of a cryptocurrency price chart on a screen
TECHNOLOGY

XRPH Wallet Breach Hits 4,011 Accounts

Image Credit: Shutterstock

XRP Healthcare says 4,011 XRPH Wallet accounts were affected by unauthorized transactions that removed roughly $452,000 in XRP, XRPH and XRPHAI on September 3.

The project has told users to stop using XRPH Wallet while developers investigate how the attacker gained control of the affected accounts. The stolen assets were moved through NEAR Intents to Ethereum and converted into about 445,198 DAI, which remained at the identified destination address during the latest tracing.

Attacker Moved Stolen Assets to Ethereum Within Three Hours 

Independent on-chain analysis traced 267,664 XRP, 23.2 million XRPH and 2.43 million XRPHAI from affected wallets. The first sweep began at about 22:07 UTC, and the converted funds reached DAI on Ethereum roughly three hours later.

The attacker routed XRP through NEAR Intents, received ETH on Ethereum and then swapped the proceeds into DAI. XRP Healthcare published the destination address and said it is working with exchanges and other parties to flag the funds and explore possible recovery. 

No assets have been confirmed recovered. XRP Healthcare reports 4,011 affected accounts, while a separate ledger review identified 4,010 victim wallets plus one transaction used by the attacker to fund the collection address.

Researchers Find Staking Code Sent Seed Phrases to Server 

Researchers examining XRPH Wallet version 8.0.15 found that its staking function transmitted a user’s seed phrase to an XRP Healthcare server when staking or unstaking. Of the affected wallets examined, 1,199 had used the staking feature. 

That finding does not explain the full breach because nearly 70% of the drained wallets had not staked. Investigators have not established how the attacker obtained credentials for those accounts.

The review also found wallet seeds stored unencrypted in the application’s local database, although accessing that data directly would normally require control of the device or elevated malware permissions.

XRP Healthcare Has Not Confirmed Breach Root Cause 

XRP Healthcare has described XRPH Wallet as noncustodial and said it was unaware that part of the staking functionality operated differently. It has asked the developers responsible for the wallet for an explanation.

A full developer report remains pending, and XRP Healthcare has not confirmed the method used to gain access to the affected accounts.

The project is continuing to advise users not to use XRPH Wallet while the investigation remains open.

More For You

Explore More News