An attack against users of the D’CENT App Wallet resulted in the misappropriation of 11.746 million XRP, or nearly $20 million. Between September 15 and 20, 6,678 wallets were affected in six waves. More than 5.59 million XRP has already left the network via THORChain. The case does not come from a flaw in the XRP Ledger: the crypto transactions were signed with private keys that the attacker controlled. D’CENT is still investigating how these keys were compromised.

In brief
- 11.746 million XRP were withdrawn from 6,678 wallets between September 15 and 20.
- Over 5.59 million XRP has been converted to Ethereum via THORChain.
- D’CENT claims that its hardware wallets are not directly affected unless their recovery phrase has been entered into the App Wallet.
Six waves emptied 6,678 D’CENT wallets
The attack began on September 15 with eight large wallets. They each held at least 99,999 XRP. The operator starts manually and withdraws over 1.6 million XRP before even launching the script used for the rest of the operation. A few hours later, 1,682 wallets have already been affected.
This type of compromise is taking an increasing part in the sector’s losses. Tremplin.io noted this summer that private key theft, phishing and wallet compromises were now responsible for a significant portion of crypto hacks.
After a calm day on September 16, withdrawals resume. Five new waves follow one another until September 20. In total, XRPL.to’s on-chain analysis identifies 4,208 wallets emptied by transfer. To this are added 2,470 accounts which had not been swept before but were directly deleted with the balance they contained.
The attackers used the keys a second time to delete 5,001 XRP accounts and recover their remaining reserves. In one case, a wallet still active since 2022 contained more than 107,000 XRP at the time of its deletion.
The crypto attack therefore seems to have been prepared with a list already constituted. XRPL.to even notes that the largest wallets were processed manually, while the others went through different scripts.
More than 5.5 million XRP have already left the network
The funds did not wait long. 5,594,530 XRP was sent to THORChain and then exchanged to Ethereum. Around 3.24 million XRP also went through unionchain.ai, 546,080 XRP through NEAR Intents, and 535,666 XRP to Binance deposit addresses. These services are not accused of having participated in the theft: they simply appear in the on-chain journey of funds.
As of September 21, approximately 1.308 million XRP still remained in wallets allocated to the operator.
For a crypto attack, this rapid dispersion poses a fairly classic problem. The more funds pass through swaps, bridges or several platforms, the more complicated their freezing becomes. D’CENT says it works with South Korean law enforcementsecurity specialists, the teams of the blockchains concerned and the exchanges in order to track the assets and try to block part of them. However, the company does not promise their recovery.
This is not the first time crypto wallets have been serially emptied this year. As early as January, several hundred EVM wallets were affected in another operation, with much smaller amounts per victim.
In the D’CENT file, the scale is different: almost $20 million in XRP in less than a week. However, the XRP Ledger itself has not been compromised. Each movement appears as an ordinary transaction, validly signed. Blockchain can show when keys have been used and where funds have gone. She cannot explain how these keys got into the hands of the attacker.
Private keys bring crypto security back to the forefront
D’CENT makes an important distinction between its two products. The hardware wallet creates and stores keys on a physical device. The mobile application is then mainly used to display addresses and balances. The recovery phrase is not automatically copied to the phone. Conversely, the App Wallet is a software wallet: the keys are created or imported directly on the smartphone. It is this second mode that D’CENT associated with abnormal transfers.
There is, however, one exception. A hardware wallet can enter the perimeter if its user has already entered their recovery phrase in the App Wallet. D’CENT then recommends considering this sentence as potentially exposed.
The company is asking affected users to update the app, create a new recovery phrase and then move their crypto assets to new addresses. Simply restoring the old seed to new media does not change the keys and therefore does not solve the problem.
The exact technical cause remains publicly unknown. D’CENT is continuing its analysis and has not yet announced a conclusion on a possible reimbursement.
The incident joins a series of cases where the private key, rather than the smart contract, becomes the entry point. In June, the Humanity Protocol hack had already put this risk at the center of crypto news after more than $32 million in losses. Humanity Protocol falls by more than 80% after a $32 million hack For D’CENT, the numbers are already heavy: 6,678 wallets, 11.746 million XRP and six days of activity. The investigation must still answer the most important question: how could the same list of private keys end up in the hands of the attacker?
Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
