XRP Ledger Hack Exposes Years-Old Red Flags in XRP Healthcare
A security incident on XRP Ledger's ecosystem has led to the theft of approximately 267,000 XRP and millions of related tokens. The attack occurred within three hours on September 3, 2026, when attackers drained the balances of thousands of users from mobile wallets belonging to XRP Healthcare, formerly known as XRPayNet.
A critical bug was discovered through forensic analysis: users' private seed phrases were sent to a server when staking features were activated. This vulnerability had been identified years ago by security experts and former Ripple employees, who had blacklisted the project due to its suspicious behavior.
The team behind XRP Healthcare has denied any wrongdoing, accusing former Ripple developers of unethical behavior for publicly celebrating the misfortune of colleagues. However, former developers have maintained that they had previously rejected grant applications from the team due to their suspicions about the project's legitimacy.