A major security breach has struck XRP Healthcare, a blockchain project within the XRP Ledger (XRPL) ecosystem, resulting in the theft of approximately 267,000 XRP and millions of related tokens from thousands of users’ mobile wallets.
XRPL vulnerability exposes user seed phrases
On September 3, 2026, attackers exploited a critical vulnerability in mobile wallets connected to XRP Healthcare, a Uganda-based medical initiative that previously operated as XRPayNet. Within just three hours, the perpetrators were able to drain account balances and swiftly move the stolen assets to the Ethereum network, making recovery efforts more challenging.
A forensic analysis revealed that the breach stemmed from a major flaw in the wallet’s staking feature. When users activated staking, their private seed phrases were transmitted to a remote server, leaving their funds highly vulnerable.
Mini dictionary: Private seed phrase – a unique set of words generated by a wallet that allows users to recover or access their cryptocurrency. If compromised, anyone with access to the seed phrase can control the funds in that wallet.
Blockchain developer BiasGoose signaled that the incident was not unexpected, stating he had previously rejected grant applications from the project team due to concerns about its practices.
Developers air past warnings, project responds to criticism
Former Ripple developers, who had previously distanced themselves from XRP Healthcare, pointed to warning signs dating back to the project’s early days. BiasGoose, who works closely with XRPL-funded initiatives, claimed the team was caught making misleading statements in grant applications, including fabricating partnerships to attract funding.
BiasGoose pointed out that the project “didn’t need a token in the first place” and cited false partnership claims as a persistent issue in their funding requests.
Project representatives confirmed the theft and announced an urgent investigation. They said they were tracking the stolen funds on the blockchain and working with authorities to freeze assets and recover users’ holdings. Meanwhile, the team rebuked critics, arguing that public mockery from former Ripple developers was unfair and unprofessional, given the risk and responsibility assumed by those involved in recovery efforts.
The affected team emphasized their disappointment: they had “expected far more character from industry veterans” instead of ridicule during a crisis.
Community debates negligence and project credibility
The escalation between XRP Healthcare’s team and former Ripple engineers played out publicly on X, with both sides defending their actions. BiasGoose responded to criticism by highlighting that he had “never taken risks with other people’s money,” further intensifying the dispute.
As XRP Healthcare attempts to recover lost assets and restore user trust, the broader crypto community is left to consider whether the loss was an unforeseeable mistake or a long-predicted failure rooted in ignored warning signs and project mismanagement.





USDT
AAPL
