XRP: 11.7 Million Tokens Vanish From Thousands of D’CENT Wallets
An attack against users of the D’CENT App Wallet allowed the diversion of 11.746 million XRP, nearly 20 million dollars. Between September 15 and 20, 6,678 wallets were affected in six waves. More than 5.59 million XRP have already left the network via THORChain. The case does not come from a flaw in the XRP Ledger: the crypto transactions were signed with private keys controlled by the attacker. D’CENT is still investigating how these keys were compromised.

In brief
- 11.746 million XRP were withdrawn from 6,678 wallets between September 15 and 20.
- More than 5.59 million XRP were converted to Ethereum via THORChain.
- D’CENT states that its hardware wallets are not directly affected unless their recovery phrase was entered in the App Wallet.
Six waves emptied 6,678 D’CENT wallets
The attack started on September 15 with eight large wallets. Each held at least 99,999 XRP. The operator began manually and withdrew more than 1.6 million XRP even before launching the script used for the rest of the operation. A few hours later, 1,682 wallets had already been affected.
This type of compromise is an increasing part of sector losses. Cointribune noted this summer that private key thefts, phishing, and wallet compromises now account for a significant share of crypto hacks.
After a calm day on September 16, withdrawals resumed. Five new waves followed until September 20. In total, XRPL.to’s on-chain analysis lists 4,208 wallets emptied by transfer. Additionally, 2,470 accounts that hadn’t been touched before were directly deleted with their balance.
The attackers used the keys a second time to delete 5,001 XRP accounts and recover their remaining reserves. In one case, a wallet active since 2022 contained over 107,000 XRP at the time of deletion.
The crypto attack thus seems to have been prepared with a pre-existing list. XRPL.to even notes that the largest wallets were handled manually, while the others went through various scripts.
More than 5.5 million XRP have already left the network
The funds did not wait long. 5,594,530 XRP were sent to THORChain then exchanged for Ethereum. About 3.24 million XRP also passed through unionchain.ai, 546,080 XRP via NEAR Intents, and 535,666 XRP to Binance deposit addresses. These services are not accused of participating in the theft: they simply appear in the on-chain journey of the funds.
As of September 21, about 1.308 million XRP still remained in wallets assigned to the operator.
For a crypto attack, this rapid dispersion poses a fairly classic problem. The more funds go through swaps, bridges, or platforms, the harder it becomes to freeze them. D’CENT says it is working with South Korean law enforcement, security specialists, blockchain teams, and exchanges to track assets and try to block part of them. However, the company does not promise their recovery.
This is not the first time crypto wallets have been emptied in series this year. In January, several hundred EVM wallets were affected in another operation, with much smaller amounts per victim.
In the D’CENT case, the scale is different: nearly 20 million dollars in XRP in less than a week. Yet the XRP Ledger itself was not compromised. Each movement appears as an ordinary transaction, validly signed. The blockchain can show when the keys were used and where the funds went. It cannot explain how these keys ended up in the attacker’s hands.
Private keys put crypto security back in the spotlight
D’CENT makes an important distinction between its two products. The hardware wallet creates and stores keys on a physical device. The mobile app mainly displays addresses and balances. The recovery phrase is not automatically copied to the phone. Conversely, the App Wallet is a software wallet: keys are created or imported directly on the smartphone. It is this second mode that D’CENT associated with the abnormal transfers.
There is however an exception. A hardware wallet can fall within scope if its user has already entered the recovery phrase in the App Wallet. D’CENT then recommends considering this phrase as potentially exposed.
The company asks affected users to update the app, create a new recovery phrase, then move their crypto assets to new addresses. Simply restoring the old seed on a new device does not change the keys and thus does not solve the problem.
The exact technical cause remains publicly unknown. D’CENT continues its analysis and has not yet announced any conclusion on possible reimbursement.
The incident joins a series of cases where the private key, rather than the smart contract, becomes the entry point. In June, the Humanity Protocol hack brought this risk back to the center of crypto news after over 32 million dollars in losses. Humanity Protocol drops over 80% after a 32 million dollar hack. For D’CENT, the numbers are already heavy: 6,678 wallets, 11.746 million XRP, and six days of activity. The investigation still has to answer the most important question: how could the same list of private keys have ended up in the attacker’s hands?
Maximize your Cointribune experience with our "Read to Earn" program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
Fascinated by Bitcoin since 2017, Evariste has continuously researched the subject. While his initial interest was in trading, he now actively seeks to understand all advances centered on cryptocurrencies. As an editor, he strives to consistently deliver high-quality work that reflects the state of the sector as a whole.
The views, thoughts, and opinions expressed in this article belong solely to the author, and should not be taken as investment advice. Do your own research before taking any investment decisions.