
In a significant development shaking the XRP Ledger community, XRP Healthcare has announced it is winding down operations following a critical flaw in its wallet that resulted in the theft of approximately $450,000. The incident, which affected around 4,010 wallets, has temporarily suspended the project's digital services as security and recovery efforts are underway. This event serves as a stark reminder of the persistent threats of crypto-asset theft and the vulnerabilities that can plague even specialized digital wallets.
在震動 XRP Ledger 社群的一項重大進展中,XRP Healthcare 宣布,由於其錢包有嚴重缺陷,導致約 45 萬美元被盜,該公司將停止營運。該事件影響了約 4,010 個錢包,由於安全和恢復工作正在進行中,該項目的數位服務已暫時停止。這起事件清楚地提醒人們,加密資產竊盜的持續威脅以及甚至可能困擾專業數位錢包的漏洞。
XRP Healthcare Faces Fallout from Wallet Vulnerability
XRP 醫療保健面臨錢包漏洞的影響
The core of XRP Healthcare's troubles stems from a wallet flaw identified on September 3, 2026. A developer report detailed how a malformed input string into the `xrpl.Wallet.fromEntropy()` function led to a drastically reduced keyspace, making wallet keys susceptible to brute-force attacks. While the intended keyspace was an expansive 2^128, the flaw narrowed it down to roughly 2^46.05. This critical vulnerability, traced back to a code commit in June 2023 and present in the pre-incident release from July 2026, allowed malicious actors to drain an estimated $450,000 across thousands of wallets. The project has confirmed that all wallets generated by the application must be considered compromised, necessitating new key generation for affected users.
XRP Healthcare 問題的核心源自於 2026 年 9 月 3 日發現的錢包缺陷。開發人員報告詳細介紹了「xrpl.Wallet.fromEntropy()」函數中格式錯誤的輸入字串如何導致金鑰空間大幅減少,從而使錢包金鑰容易受到暴力攻擊。雖然預期的密鑰空間為 2^128,但該缺陷將其縮小到大約 2^46.05。這個嚴重漏洞可追溯到 2023 年 6 月提交的程式碼,並存在於 2026 年 7 月的事件前發布中,導致惡意攻擊者從數千個錢包中盜取了約 45 萬美元。該項目已確認該應用程式產生的所有錢包都必須被視為已受到損害,因此需要為受影響的用戶產生新的金鑰。
Broader Implications: A Wave of Crypto-Asset Theft
更廣泛的影響:加密資產竊盜浪潮
The XRP Healthcare incident is not an isolated event, but rather part of a larger, concerning trend in cryptocurrency security. Security researchers recently uncovered a large-scale crypto wallet theft campaign involving 77 malicious Firefox browser extensions. These extensions, active since at least March 2026, employed sophisticated tactics to steal user credentials. Some mimicked legitimate wallet tools like OKX and Rabby Wallet, using subtle alterations like replacing 'O' with '0' in their names. Others acted as seemingly harmless sports score apps that hid malicious code, allowing attackers to remotely switch them into fake wallet pages. A particularly alarming method involved copying and modifying the code of real wallets, such as Rabby Wallet, to silently capture recovery phrases during the wallet setup process.
XRP 醫療保健事件不是孤立的事件,而是加密貨幣安全領域更大的、令人擔憂的趨勢的一部分。安全研究人員最近發現了一起涉及 77 個惡意 Firefox 瀏覽器擴充功能的大規模加密錢包盜竊活動。這些擴充功能至少自 2026 年 3 月起就一直活躍,採用複雜的策略來竊取用戶憑證。有些模仿 OKX 和 Rabby Wallet 等合法錢包工具,使用細微的更改,例如將名稱中的“O”替換為“0”。其他應用程式看似無害的體育比分應用程式隱藏了惡意程式碼,允許攻擊者遠端將它們切換到假錢包頁面。一種特別令人震驚的方法涉及複製和修改真實錢包(例如 Rabby Wallet)的程式碼,以在錢包設定過程中靜默捕捉恢復短語。
Tactics and Deception in Digital Asset Theft
數位資產竊盜中的策略和欺騙
The methods used by these malicious extensions highlight the evolving nature of crypto-asset theft. Beyond outright scams, attackers are increasingly using social engineering and code manipulation. Some extensions leveraged remote loading via services like Supabase, enabling attackers to change the extension's functionality without requiring an update. Others directly intercepted sensitive information, like recovery phrases or saved passwords, before they could be properly encrypted or secured. These operations often shared common infrastructure or codes, like the `EQOx7EIPZSNi` label found across multiple extensions, pointing to a coordinated effort by a single group or a shared toolkit. While Mozilla has removed many of these extensions, the episode underscores the constant vigilance required from users.
這些惡意擴展所使用的方法凸顯了加密資產盜竊的不斷演變的性質。除了徹頭徹尾的詐騙之外,攻擊者也越來越多地使用社會工程和程式碼操縱。一些擴充功能透過 Supabase 等服務利用遠端加載,使攻擊者無需更新即可更改擴展的功能。其他人在正確加密或保護敏感資訊之前直接攔截敏感資訊,例如恢復短語或保存的密碼。這些操作通常共用通用的基礎設施或程式碼,例如在多個擴充功能中發現的「EQOx7EIPZSNi」標籤,表示單一群組或共用工具包的協調工作。儘管 Mozilla 已經刪除了其中許多擴展,但這一事件凸顯了用戶需要時刻保持警惕。
Uncertainty for Affected Holders and Future Outlook
受影響持有者的不確定性與未來前景
For those affected by the XRP Healthcare wallet theft, a cloud of uncertainty remains. The full extent of fund recovery is unclear, and details regarding reimbursements or access to any remaining funds are still being finalized. The project's official statements confirm ongoing recovery efforts and a temporary suspension of services, but a precise shutdown schedule and verified instructions for holders are pending. This situation, coupled with factors like development costs, a prolonged bear market, and an unsuccessful public listing effort, contributed to the decision to wind down operations. While this project-level event does not implicate the broader XRP Ledger, it underscores the critical importance of rigorous security auditing and user education in the rapidly expanding digital asset ecosystem.
對於那些受到 XRP Healthcare 錢包失竊影響的人來說,不確定性仍然存在。資金回收的全部範圍尚不清楚,有關報銷或使用任何剩餘資金的細節仍在最終確定中。該專案的官方聲明確認了正在進行的恢復工作和暫時暫停的服務,但具體的關閉時間表和針對持有者的經過驗證的指示仍在等待中。這種情況,再加上開發成本、長期熊市以及公開上市努力不成功等因素,導致了關閉業務的決定。雖然這一專案級事件並不涉及更廣泛的 XRP 帳本,但它強調了嚴格的安全審計和用戶教育在快速擴張的數位資產生態系統中的至關重要性。
So, while it's a tough break for XRP Healthcare and its users, let's all take a moment to double-check those wallet permissions and maybe, just maybe, consider a hardware wallet for your most precious digital treasures. Stay safe out there, crypto adventurers!
因此,雖然這對 XRP Healthcare 及其用戶來說是一個艱難的突破,但讓我們花點時間仔細檢查這些錢包權限,也許,只是也許,考慮為您最珍貴的數位財富使用硬體錢包。加密貨幣冒險家們,請保持安全!
36crypto
Cointribune EN
Coingabbar
IT Times
Coinpaper.com
Coingabbar
DT News
ETHNews
36crypto