
In a significant development shaking the XRP Ledger community, XRP Healthcare has announced it is winding down operations following a critical flaw in its wallet that resulted in the theft of approximately $450,000. The incident, which affected around 4,010 wallets, has temporarily suspended the project's digital services as security and recovery efforts are underway. This event serves as a stark reminder of the persistent threats of crypto-asset theft and the vulnerabilities that can plague even specialized digital wallets.
XRP Ledgerコミュニティを揺るがす重大な進展の中で、XRP Healthcareは、約45万ドルの盗難につながったウォレットの重大な欠陥を受けて、業務を終了すると発表した。この事件は約4,010のウォレットに影響を及ぼし、セキュリティと復旧の取り組みが進行中であるため、プロジェクトのデジタルサービスは一時的に停止されました。この出来事は、暗号資産盗難の根強い脅威と、特殊なデジタルウォレットさえも悩まし得る脆弱性をはっきりと思い出させるものとなっています。
XRP Healthcare Faces Fallout from Wallet Vulnerability
XRPヘルスケアがウォレットの脆弱性によるフォールアウトに直面
The core of XRP Healthcare's troubles stems from a wallet flaw identified on September 3, 2026. A developer report detailed how a malformed input string into the `xrpl.Wallet.fromEntropy()` function led to a drastically reduced keyspace, making wallet keys susceptible to brute-force attacks. While the intended keyspace was an expansive 2^128, the flaw narrowed it down to roughly 2^46.05. This critical vulnerability, traced back to a code commit in June 2023 and present in the pre-incident release from July 2026, allowed malicious actors to drain an estimated $450,000 across thousands of wallets. The project has confirmed that all wallets generated by the application must be considered compromised, necessitating new key generation for affected users.
XRP Healthcareの問題の核心は、2026年9月3日に特定されたウォレットの欠陥に起因しています。開発者レポートでは、「xrpl.Wallet.fromEntropy()」関数への不正な入力文字列によってキースペースが大幅に減少し、ウォレットのキーがブルートフォース攻撃を受けやすくなった経緯が詳しく説明されています。意図されたキースペースは広大な 2^128 でしたが、この欠陥によりキースペースはおよそ 2^46.05 に狭まりました。この重大な脆弱性は、2023 年 6 月のコードコミットに遡り、2026 年 7 月の事件前のリリースに存在しており、悪意のある攻撃者が数千のウォレットで推定 45 万ドルを流出させる可能性がありました。プロジェクトは、アプリケーションによって生成されたすべてのウォレットが侵害されたとみなされる必要があり、影響を受けるユーザーには新しいキーの生成が必要であることを確認しました。
Broader Implications: A Wave of Crypto-Asset Theft
より広範な影響: 暗号資産盗難の波
The XRP Healthcare incident is not an isolated event, but rather part of a larger, concerning trend in cryptocurrency security. Security researchers recently uncovered a large-scale crypto wallet theft campaign involving 77 malicious Firefox browser extensions. These extensions, active since at least March 2026, employed sophisticated tactics to steal user credentials. Some mimicked legitimate wallet tools like OKX and Rabby Wallet, using subtle alterations like replacing 'O' with '0' in their names. Others acted as seemingly harmless sports score apps that hid malicious code, allowing attackers to remotely switch them into fake wallet pages. A particularly alarming method involved copying and modifying the code of real wallets, such as Rabby Wallet, to silently capture recovery phrases during the wallet setup process.
XRP ヘルスケアのインシデントは個別の出来事ではなく、むしろ仮想通貨のセキュリティにおけるより大きな懸念される傾向の一部です。セキュリティ研究者は最近、77 の悪意のある Firefox ブラウザ拡張機能が関与した大規模な暗号通貨ウォレット盗難キャンペーンを発見しました。これらの拡張機能は、少なくとも 2026 年 3 月以降活動しており、ユーザーの認証情報を盗むために高度な戦術を採用していました。一部は、名前の「O」を「0」に置き換えるなどの微妙な変更を使用して、OKX や Rabby Wallet などの正規のウォレット ツールを模倣しました。他のものは、悪意のあるコードを隠し、攻撃者がリモートから偽のウォレット ページに切り替えることを可能にする、一見無害なスポーツ スコア アプリとして機能しました。特に憂慮すべき方法には、Rabby Wallet などの実際のウォレットのコードをコピーして変更し、ウォレットのセットアップ プロセス中にリカバリ フレーズをサイレントにキャプチャすることが含まれていました。
Tactics and Deception in Digital Asset Theft
デジタル資産盗難における戦術と欺瞞
The methods used by these malicious extensions highlight the evolving nature of crypto-asset theft. Beyond outright scams, attackers are increasingly using social engineering and code manipulation. Some extensions leveraged remote loading via services like Supabase, enabling attackers to change the extension's functionality without requiring an update. Others directly intercepted sensitive information, like recovery phrases or saved passwords, before they could be properly encrypted or secured. These operations often shared common infrastructure or codes, like the `EQOx7EIPZSNi` label found across multiple extensions, pointing to a coordinated effort by a single group or a shared toolkit. While Mozilla has removed many of these extensions, the episode underscores the constant vigilance required from users.
これらの悪意のある拡張機能が使用する手法は、暗号資産盗難の進化する性質を浮き彫りにしています。攻撃者は、完全な詐欺にとどまらず、ソーシャル エンジニアリングやコード操作をますます使用しています。一部の拡張機能は、Supabase などのサービスを介したリモート読み込みを利用しており、攻撃者が更新を必要とせずに拡張機能の機能を変更できるようにしていました。リカバリ フレーズや保存されたパスワードなどの機密情報が、適切に暗号化または保護される前に直接傍受されるものもありました。これらの操作は、複数の拡張機能にまたがる「EQOx7EIPZSNi」ラベルのような共通のインフラストラクチャやコードを共有することが多く、単一のグループまたは共有ツールキットによる調整された取り組みを示しています。 Mozilla はこれらの拡張機能の多くを削除しましたが、このエピソードはユーザーが常に警戒する必要があることを強調しています。
Uncertainty for Affected Holders and Future Outlook
影響を受ける保有者にとっての不確実性と将来の見通し
For those affected by the XRP Healthcare wallet theft, a cloud of uncertainty remains. The full extent of fund recovery is unclear, and details regarding reimbursements or access to any remaining funds are still being finalized. The project's official statements confirm ongoing recovery efforts and a temporary suspension of services, but a precise shutdown schedule and verified instructions for holders are pending. This situation, coupled with factors like development costs, a prolonged bear market, and an unsuccessful public listing effort, contributed to the decision to wind down operations. While this project-level event does not implicate the broader XRP Ledger, it underscores the critical importance of rigorous security auditing and user education in the rapidly expanding digital asset ecosystem.
XRP Healthcare ウォレットの盗難の被害を受けた人々にとって、不確実性は依然として残っています。資金回収の全容は不明であり、償還や残りの資金へのアクセスに関する詳細はまだ最終決定中である。プロジェクトの公式声明では、継続的な復旧作業とサービスの一時停止が確認されていますが、正確な停止スケジュールと所有者に対する検証済みの指示は保留中です。この状況に、開発コスト、長期にわたる弱気市場、上場努力の失敗などの要因が加わり、事業縮小の決定につながりました。このプロジェクトレベルのイベントは、より広範なXRP Ledgerに関係するものではありませんが、急速に拡大するデジタル資産エコシステムにおける厳格なセキュリティ監査とユーザー教育の重要性を強調しています。
So, while it's a tough break for XRP Healthcare and its users, let's all take a moment to double-check those wallet permissions and maybe, just maybe, consider a hardware wallet for your most precious digital treasures. Stay safe out there, crypto adventurers!
したがって、XRP Healthcareとそのユーザーにとっては厳しい休暇ではありますが、皆さんも少し時間を取ってウォレットの権限を再確認し、おそらく、おそらく、最も貴重なデジタル宝物のためにハードウェアウォレットを検討してみましょう。暗号通貨冒険家の皆さん、安全を確保してください!
36crypto
Cointribune EN
Coingabbar
IT Times
Coinpaper.com
Coingabbar
DT News
ETHNews
36crypto