On September 3, 2026, the XRPH Wallet was exploited, draining $452,000 across 4,011 accounts. Independent analysis revealed a backend seed phrase leak, sparking a public feud with former Ripple developers who cited years of ignored red flags.
An exploit targeting the XRPH Wallet (associated with XRP Healthcare, formerly XRPayNet) resulted in the unauthorized drain of 4,011 user wallets, resulting in losses of roughly $452,000. The stolen funds included over 267,000 XRP and millions of XRPH tokens, which were bridged to Ethereum and converted into 445,000 DAI.
While initial speculation pointed toward network-level vulnerabilities, XRP Healthcare confirmed that the base XRP Ledger (XRPL) was not at fault. Instead, independent forensic decompilations of the XRPH Wallet Android app (build 8.0.15) uncovered a flaw: activating the wallet's staking functionality transmitted users' unencrypted seed phrases to a remote backend server.
Anatomy of the Incident
The Attack Vector: A seed phrase exposure path embedded inside the app's staking flow allowed third parties (or a compromised server) to collect master recovery keys, allowing remote drains without physical device access.
Speed of On-Chain Capital Flight: Attackers swept the funds within three hours, moving tokens across NEAR Intents to Ethereum, swapping them on Uniswap V4, and parking the resulting DAI in a single address.
The Developer Feud & Red Flags: The hack reignited longstanding criticism from prominent former Ripple developers. Security figures disclosed that previous grant applications for the project had been rejected due to "obvious red flags," questionable architectural choices, and misleading partnership claims dating back to 2022–2024.
How to Protect Your Funds
If you have ever used or imported a seed phrase into the XRPH Wallet, assume your seed phrase is compromised.
Stop Using the XRPH Wallet App: Do not interact with or attempt to recover funds inside the compromised app.
Generate a Completely Fresh Wallet: Do not simply update the app and keep your existing secret key. Create a brand-new seed phrase on an independent, vetted hardware or open-source software wallet.
Migrate Remaining Assets Immediately: Transfer any remaining tokens on-chain to your newly generated addresses.
Beware of Recovery Scams: Reject any unsolicited direct messages on X, Telegram, or Discord offering "wallet restoration" or asking for your seed phrase.
Build True Operational Security at Our Academy
This incident highlights a foundational truth in Web3: "non-custodial" interfaces are only as safe as their underlying code. When application developers route private keys through remote servers or unverified API paths, self-custody is broken.
Want to learn how to independently audit software wallets, analyze open-source codebases, and avoid compromised applications?
Join our upcoming Academy Program to master key security principles:
Decompiling & App Inspection: How to verify if a mobile wallet is leaking seed phrases or API telemetry.
True Self-Custody Hygiene: Generating hardware-bound keys using physical entropy.
On-Chain Forensics: Tracking exploiter trails across cross-chain bridges, DEXs, and mixers.
Due Diligence Frameworks: How to spot project red flags, fake partnerships, and architectural flaws before depositing funds.
Don't wait for a compromised app update to put your assets at risk. Reserve your spot at our academy today!