XRP Ledger Hack Exposes Security Risks in XRPL-Based Projects
A large-scale hack hit the XRP Ledger (XRPL) ecosystem, affecting thousands of mobile wallets at once. On September 3rd, an attacker siphoned user balances for about three hours, stealing 267,000 XRP and millions of related tokens from around 4,000 XRP Healthcare mobile wallets.
The stolen assets were immediately moved to the Ethereum network. Forensic analysis found that when users activated staking in their XRP Healthcare wallets, their private seed phrases were sent to a server, allowing attackers to access a structure that enabled large-scale asset outflows.
Former Ripple developers Biased Goose and Hazard Cookie pointed out that warning signs existed from the start, citing architectural risks documented by auditors for years. They claimed the project showed signs of fraud, openly lied about partnerships to secure funding, and created artificial hype.
The XRP Healthcare team issued an official statement acknowledging the hack, stating they are conducting an emergency investigation, tracking all blockchain transaction flows, and working with relevant authorities to freeze and recover assets.