A large-scale hack hit the XRP Ledger (XRPL) ecosystem, with thousands of mobile wallets drained at once.
On Sept. 6, blockchain outlet U.Today reported that the incident occurred on Sept. 3 in XRP Healthcare's mobile wallets, affecting about 4,000 wallets.
The attacker siphoned user balances for about 3 hours, stealing 267,000 XRP and millions of related tokens. The stolen assets were immediately moved to the Ethereum network. XRP Healthcare is a project previously known as XRPayNet.
A critical flaw linked to a staking function was cited as the cause. Forensic analysis found that when users activated staking, their private seed phrases were sent to a server. With sensitive recovery information transmitted to an external server, attackers were able to access a structure that enabled large-scale asset outflows.
After the incident, the controversy spread beyond the hack itself to the project's past. Developer Biased Goose (바이어스구스) said the case was not new to him and that he had previously rejected this team's grant application. He claimed the project showed signs of fraud from the start and openly lied about partnerships to secure funding and create artificial hype.
Biased Goose also pointed out that the product did not need its own token in the first place. He said that whatever form the service took, it did not require a token. The remarks were read as criticism that the project structure relied on unnecessary token issuance.
Security experts formerly at Ripple raised similar issues. Hazard Cookie (해저드 쿠키) and Matt Hamilton (맷 해밀턴) confirmed that auditors had documented architectural risks in the project for years. In the community, some said the team had already been treated as a problematic project in a previous market phase between 2022 and 2024.
The project team issued an official statement acknowledging the hack. The platform said developers were conducting an emergency investigation, tracking all blockchain transaction flows and working with relevant authorities to freeze and recover assets.
The project team also criticized the response from former Ripple developers. They said they were pursuing the business with their real names and money on the line, but the other side was mocking the risks borne by others, adding that openly welcoming a colleague's misfortune was sincerely pathetic. They added they expected much better decorum from industry veterans.
In response, Biased Goose countered that unlike the makers of the hacked app, he had never taken risks with other people's money. The dispute has entered a lull after heated exchanges on X, the report said.
The incident has resurfaced concerns over security checks and credibility verification for XRPL-based projects, beyond a simple wallet hack. The project team is focusing on tracking and recovering the stolen assets, while former Ripple developers argue it was a foretold incident based on old audit records and past conduct. The remaining question is whether the leak stemmed from a fatal mistake during development or the realization of long-accumulating warning signs.