D’CENT app wallet attack drains 12.4M XRP from thousands of users over 10-day spree

1 hour ago 22

A security breach targeting the D’CENT App Wallet has resulted in the theft of approximately 12.4 million XRP from 7,393 wallets, with attackers exploiting compromised private keys over a 10-day window stretching from September 15 to September 25. The stolen funds were systematically drained in waves, and roughly half has already been laundered through cross-chain swaps.

The first wave was the worst. On September 15, attackers drained around 3.6 million XRP from 1,682 wallets in under three hours, using a combination of manual and automated methods. That’s the kind of speed that suggests pre-positioned access rather than a real-time exploit, meaning the key compromise likely predated the actual theft by some margin.

How the attack unfolded

Users began flagging suspicious activity on September 16, one day after the initial wave hit. On-chain analysis confirmed a pattern of unauthorized transfers originating from wallets tied to D’CENT’s App Wallet, specifically versions older than 8.1.0, which was released on November 5, 2025.

The vulnerability appears to be tied to how private keys were handled in those older app versions. D’CENT has not fully disclosed the exact mechanism behind the key compromise.

Hardware wallet users were not affected, unless they had imported their recovery seed phrase into the compromised app. The attack vector was software-side, not a firmware-level flaw in D’CENT’s biometric hardware wallet product.

Even after public warnings circulated, the bleeding continued. More than 640,000 XRP was stolen after September 21, suggesting either that some users hadn’t seen the alerts or that automated scripts were still running against wallets whose keys had already been extracted. By the time on-chain observers tallied the damage, 6,095 accounts had been deleted entirely.

Following the money

Roughly 6.3 million XRP, just over half the total haul, has already been laundered. Attackers swapped the stolen XRP to Ethereum using THORChain, a decentralized cross-chain liquidity protocol that doesn’t require user identification. From there, the funds were routed to centralized exchanges including Binance.

As of September 25, approximately 1.4 million XRP remained in monitored attacker-controlled addresses, with activity still ongoing. D’CENT says it is working with law enforcement to trace and freeze stolen funds.

Users have been warned not to send XRP to old wallet addresses and to avoid reusing recovery phrases that were ever entered into the compromised app versions.

Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article