This XRP project is shutting down after wallet flaw exposed 4,000 accounts and drained $450,000

8 hours ago 4

XRP Healthcare, an healthcare platform build on the XRP Ledger (XRPL), is winding down operations after a wallet flaw exposed thousands of accounts and led to roughly $450,000 in losses.

On Sept. 10, the project said the Sept. 3 XRPH Wallet incident added financial and operational pressure to a business already burdened by development costs, a prolonged crypto bear market and an unsuccessful public-listing effort.

Due to this, the platform said it was preparing to delist its tokens, including XRPH and XRPHAI, with individual exchanges expected to set withdrawal deadlines. The XRPH Wallet applications will remain offline while the company retains its intellectual property and global trademark portfolio.

The shutdown follows a mass sweep that XRPL.to traced across 10,281 payments from 4,011 sender wallets between Sept. 3 and Sept. 4. The analytics service classified 4,010 of those wallets as victims after determining that one sender funded the collector account.

About 267,664 XRP, 23.2 million XRPH and 2.43 million XRPHAI were moved into the identified collector, putting the value of the stolen assets at roughly $450,000 to $452,000.

Wallet flaw collapsed the keyspace protecting user funds

XRP Healthcare’s developer investigation traced the breach to how XRPH Wallet generated credentials.

The report said the application passed a 55-character value into xrpl.Wallet.fromEntropy(), which expected raw bytes. Only the first 16 characters were effectively retained, leaving 14 variable digits and reducing the possible input space to about 72.9 trillion combinations, or roughly 2^46, from the intended 2^128.

Infographic comparing XRPH Wallet's intended 2^128 key space with an effective key space of about 2^46, while noting that the exposure does not prove the attacker's exact route.

The developers also found use of Math.random(), which could have reduced the practical search space further.

The team said it reproduced private keys for nine live wallets, including four confirmed drained accounts, using public information and a partial scan of the reduced keyspace. It concluded that the defect explains the Sept. 3 drain without requiring access to user devices or the XRP Ledger protocol.

The weakness also means users cannot secure an exposed wallet simply by importing the same seed into different software. XRP Healthcare has advised affected users to abandon credentials generated through XRPH Wallet and move any remaining assets using newly created keys.

Recovery efforts will continue despite the operational wind-down.

The company said the stolen assets had been traced end-to-end to an Ethereum address holding about 445,198 DAI and asked affected users to submit factual reports on Etherscan using transaction records from their drained wallets.

XRP Healthcare said it will continue working with exchanges, platforms, authorities and other parties while preserving technical and transaction records connected to the incident.

Read Entire Article
Patroli | Crypto | | |