
In a significant development shaking the XRP Ledger community, XRP Healthcare has announced it is winding down operations following a critical flaw in its wallet that resulted in the theft of approximately $450,000. The incident, which affected around 4,010 wallets, has temporarily suspended the project's digital services as security and recovery efforts are underway. This event serves as a stark reminder of the persistent threats of crypto-asset theft and the vulnerabilities that can plague even specialized digital wallets.
在震动 XRP Ledger 社区的一项重大进展中,XRP Healthcare 宣布,由于其钱包存在严重缺陷,导致约 450,000 美元被盗,该公司将停止运营。该事件影响了约 4,010 个钱包,由于安全和恢复工作正在进行中,该项目的数字服务已暂时停止。这一事件清楚地提醒人们,加密资产盗窃的持续威胁以及甚至可能困扰专业数字钱包的漏洞。
XRP Healthcare Faces Fallout from Wallet Vulnerability
XRP 医疗保健面临钱包漏洞的影响
The core of XRP Healthcare's troubles stems from a wallet flaw identified on September 3, 2026. A developer report detailed how a malformed input string into the `xrpl.Wallet.fromEntropy()` function led to a drastically reduced keyspace, making wallet keys susceptible to brute-force attacks. While the intended keyspace was an expansive 2^128, the flaw narrowed it down to roughly 2^46.05. This critical vulnerability, traced back to a code commit in June 2023 and present in the pre-incident release from July 2026, allowed malicious actors to drain an estimated $450,000 across thousands of wallets. The project has confirmed that all wallets generated by the application must be considered compromised, necessitating new key generation for affected users.
XRP Healthcare 问题的核心源于 2026 年 9 月 3 日发现的钱包缺陷。开发人员报告详细介绍了“xrpl.Wallet.fromEntropy()”函数中格式错误的输入字符串如何导致密钥空间大幅减少,从而使钱包密钥容易受到暴力攻击。虽然预期的密钥空间为 2^128,但该缺陷将其缩小到大约 2^46.05。这一严重漏洞可追溯到 2023 年 6 月提交的代码,并存在于 2026 年 7 月的事件前发布中,导致恶意攻击者从数千个钱包中盗取了约 45 万美元。该项目已确认该应用程序生成的所有钱包都必须被视为已受到损害,因此需要为受影响的用户生成新的密钥。
Broader Implications: A Wave of Crypto-Asset Theft
更广泛的影响:加密资产盗窃浪潮
The XRP Healthcare incident is not an isolated event, but rather part of a larger, concerning trend in cryptocurrency security. Security researchers recently uncovered a large-scale crypto wallet theft campaign involving 77 malicious Firefox browser extensions. These extensions, active since at least March 2026, employed sophisticated tactics to steal user credentials. Some mimicked legitimate wallet tools like OKX and Rabby Wallet, using subtle alterations like replacing 'O' with '0' in their names. Others acted as seemingly harmless sports score apps that hid malicious code, allowing attackers to remotely switch them into fake wallet pages. A particularly alarming method involved copying and modifying the code of real wallets, such as Rabby Wallet, to silently capture recovery phrases during the wallet setup process.
XRP 医疗保健事件不是一个孤立的事件,而是加密货币安全领域更大的、令人担忧的趋势的一部分。安全研究人员最近发现了一起涉及 77 个恶意 Firefox 浏览器扩展的大规模加密钱包盗窃活动。这些扩展至少自 2026 年 3 月起就一直活跃,采用复杂的策略来窃取用户凭据。有些模仿 OKX 和 Rabby Wallet 等合法钱包工具,使用细微的更改,例如将名称中的“O”替换为“0”。其他应用程序看似无害的体育比分应用程序隐藏了恶意代码,允许攻击者远程将它们切换到假钱包页面。一种特别令人震惊的方法涉及复制和修改真实钱包(例如 Rabby Wallet)的代码,以在钱包设置过程中静默捕获恢复短语。
Tactics and Deception in Digital Asset Theft
数字资产盗窃中的策略和欺骗
The methods used by these malicious extensions highlight the evolving nature of crypto-asset theft. Beyond outright scams, attackers are increasingly using social engineering and code manipulation. Some extensions leveraged remote loading via services like Supabase, enabling attackers to change the extension's functionality without requiring an update. Others directly intercepted sensitive information, like recovery phrases or saved passwords, before they could be properly encrypted or secured. These operations often shared common infrastructure or codes, like the `EQOx7EIPZSNi` label found across multiple extensions, pointing to a coordinated effort by a single group or a shared toolkit. While Mozilla has removed many of these extensions, the episode underscores the constant vigilance required from users.
这些恶意扩展所使用的方法凸显了加密资产盗窃的不断演变的性质。除了彻头彻尾的诈骗之外,攻击者还越来越多地使用社会工程和代码操纵。一些扩展通过 Supabase 等服务利用远程加载,使攻击者无需更新即可更改扩展的功能。其他人在正确加密或保护敏感信息之前直接拦截敏感信息,例如恢复短语或保存的密码。这些操作通常共享通用的基础设施或代码,例如在多个扩展中发现的“EQOx7EIPZSNi”标签,表明单个组或共享工具包的协调工作。尽管 Mozilla 已经删除了其中许多扩展,但这一事件凸显了用户需要时刻保持警惕。
Uncertainty for Affected Holders and Future Outlook
受影响持有人的不确定性和未来前景
For those affected by the XRP Healthcare wallet theft, a cloud of uncertainty remains. The full extent of fund recovery is unclear, and details regarding reimbursements or access to any remaining funds are still being finalized. The project's official statements confirm ongoing recovery efforts and a temporary suspension of services, but a precise shutdown schedule and verified instructions for holders are pending. This situation, coupled with factors like development costs, a prolonged bear market, and an unsuccessful public listing effort, contributed to the decision to wind down operations. While this project-level event does not implicate the broader XRP Ledger, it underscores the critical importance of rigorous security auditing and user education in the rapidly expanding digital asset ecosystem.
对于那些受到 XRP Healthcare 钱包失窃影响的人来说,不确定性仍然存在。资金回收的全部范围尚不清楚,有关报销或使用任何剩余资金的细节仍在最终确定中。该项目的官方声明确认了正在进行的恢复工作和暂时暂停的服务,但具体的关闭时间表和针对持有者的经过验证的指示仍在等待中。这种情况,再加上开发成本、长期熊市以及公开上市努力不成功等因素,导致了关闭业务的决定。虽然这一项目级事件并不涉及更广泛的 XRP 账本,但它强调了严格的安全审计和用户教育在快速扩张的数字资产生态系统中的至关重要性。
So, while it's a tough break for XRP Healthcare and its users, let's all take a moment to double-check those wallet permissions and maybe, just maybe, consider a hardware wallet for your most precious digital treasures. Stay safe out there, crypto adventurers!
因此,虽然这对 XRP Healthcare 及其用户来说是一个艰难的突破,但让我们花点时间仔细检查这些钱包权限,也许,只是也许,考虑为您最珍贵的数字财富使用硬件钱包。加密货币冒险家们,请保持安全!
36crypto
Cointribune EN
Coingabbar
IT Times
Coinpaper.com
Coingabbar
DT News
ETHNews
36crypto