Newsroom
6 September, 2026 / News / AI / Tags: healthcare, xrp, biasgoose, ripple, developers

Attackers emptied thousands of mobile wallets on September 3 after a seed-phrase flaw, prompting recovery efforts and sharp public criticism from ex-Ripple figures
A security incident on the XRP Ledger has left roughly 4,011 users of the XRP Healthcare mobile wallet without their funds after attackers drained balances in a rapid three-hour window on September 3, 2026. Approximately 267,000 XRP together with millions of associated tokens were moved off the network and routed toward Ethereum.
XRP Healthcare, previously known as XRPayNet, confirmed the breach and stated that its developers are conducting an urgent on-chain investigation while working with authorities in an attempt to freeze and recover the stolen assets. The project advised users not to interact with the wallet pending further notice.
Forensic examination of the mobile application identified a critical vulnerability tied to private seed phrases. When users activated staking features, the application transmitted those seeds to a company-controlled server. In the version of the app examined, seeds were also stored unencrypted on the device itself. Investigators concluded that the attacker obtained access to the same material held by the server, enabling the mass emptying of wallets.
The drain began in the evening of September 3. Within minutes, balances from thousands of accounts flowed into a newly created collector address. The majority of the XRP was later bridged and converted, with a substantial portion ending as DAI on Ethereum. Token holdings that included more than 23 million XRPH and more than 2 million XRPHAI were also taken.
XRP Healthcare stated that it is tracing every transaction and coordinating with relevant authorities. The team has publicly acknowledged the scale of the incident and the approximate dollar value of the loss, reported near 452,000 USD at the time of the transfers. Developers continue to examine how the server-side exposure occurred and whether additional code paths beyond staking also contributed.
Community analysis of the ledger showed that the collector address received funds from thousands of distinct wallets in a short period, with the largest accounts emptied first. The speed and coordination of the transfers left little opportunity for individual users to react.
The breach quickly triggered a sharp exchange on social platform X between the project team and several former Ripple developers. BiasGoose, a former Ripple developer, stated that the incident did not surprise him. He said he had previously rejected grant applications linked to the project and alleged that the Uganda-linked healthcare initiative had made misleading partnership claims while seeking funding and generating interest. He also questioned whether the platform required its own token.
Other former Ripple-linked figures, including Hazard Cookie and Matt Hamilton, pointed to earlier concerns about the project’s architecture and security practices that they said had been raised during prior market cycles between 2022 and 2024.
XRP Healthcare responded by accusing the critics of unethical behavior and of mocking a team dealing with a serious security incident. BiasGoose countered that, unlike the application’s developers, he had never placed other people’s funds at risk.
The episode has focused attention on how mobile wallets handle seed material and on the risks that arise when sensitive data leaves a user’s device. While the project continues its recovery work, the public disagreement has also revived earlier questions about the project’s past funding applications and operational decisions.
Investigators are still following the movement of the stolen assets. XRP Healthcare maintains that it is cooperating fully with authorities in the effort to reclaim what can be recovered.









