XRP Healthcare said an initial investigation found that unauthorized transactions affected approximately 4,011 wallets and removed roughly $452,000 in digital assets. In an official update published Sept. 4 , the company said about 445,000 DAI had been traced to one Ethereum wallet and had not moved at the time of its statement.
The figures and tracing assessment are company claims from an early investigation. XRP Healthcare said recovery could not be guaranteed and did not publish a complete technical postmortem identifying how wallet keys were compromised.
The company says the XRP Ledger was not at fault
XRP Healthcare said its developers found no evidence that the XRP Ledger itself caused the incident. The affected assets included tokens used with the XRPH Wallet, but the company left the precise entry point under investigation.
That distinction matters because an application-level key leak, malicious dependency or server-side security failure would require a different response from a flaw in the underlying ledger. The statement narrows one possibility but does not establish which application component failed, when exposure began or whether every affected user followed the same path.
Funds were traced, but not recovered
The company said the assets were followed end to end and that the DAI remained at a single Ethereum address when the update was posted. It planned to pursue address blacklisting and other recovery options. A visible balance can help investigators coordinate with token issuers and exchanges, yet control remains with whoever holds the private key unless an authorized counterparty can intervene.
XRP Healthcare did not announce a reimbursement program, payment schedule or confirmed freeze. Readers should therefore separate “traced” from “recovered”: the first describes investigators locating assets on a public ledger, while the second would require the company or users to regain control.
Users still need a clean wallet environment
The company had already told users not to use XRPH Wallet while the investigation continued. If a recovery phrase or private key was exposed, an application update alone would not secure it. Our guide to how seed phrases control wallet funds explains why remaining assets must be moved to a newly generated secret rather than left under the old credentials.
A credible final postmortem should identify affected versions, the data path that exposed keys, the period of risk and the controls added afterward. Until those details arrive, users should rely only on verified company channels and reject unsolicited recovery messages that request a phrase, key or advance payment.


