Security
Most of the 11.7 Million XRP in the D'CENT Drain Left After the Warning
D'CENT told App Wallet users to move their funds on September 16. By the evening of the 20th, one operator had emptied 6,678 XRP Ledger wallets, most of that value after the notice went out, and had used the same keys to delete 5,001 accounts.
The first sweep came by hand. At 15:35 UTC on September 15, someone moved 510,108 XRP out of an XRP Ledger wallet into an address that did not exist until that payment created it. Over the next forty minutes the same tool emptied six more wallets holding 99,999 XRP or more. At 16:29 a script took over and began working through a list.
By the evening of September 20, according to a ledger reconstruction published by the XRP analytics site XRPL.to, one operator had emptied 6,678 wallets of 11,746,198 XRP in six waves. The wallet maker D'CENT, whose parent company is the South Korean firm IoTrust, did not publish its first warning until September 16. On XRPL.to's figures, the first day accounts for 3,618,110 XRP. The remaining 8.1 million or so, roughly 69 percent, came after the notice.
What D'CENT has said
D'CENT's September 16 notice said it had detected abnormal transfers involving the App Wallet, the software wallet inside its phone app, as distinct from its hardware devices. It told anyone holding assets there, and anyone who had typed a hardware-wallet recovery phrase into the app, to move their funds.
The company's preliminary incident report, dated September 17 and titled "App Wallet Signing Vulnerability," narrows the scope considerably. An address is at risk if its recovery phrase was entered into the App Wallet and it has signing history, meaning transfers, approvals or dApp interactions, from app versions earlier than 8.1.0. The report lists Bitcoin, Ethereum, the XRP Ledger, TRON and EVM-based chains. The first irregular transactions were seen on Android, but D'CENT says the same potential impact applies to iOS.
Version 8.1.0 shipped on November 5, 2025. D'CENT's self-check guide uses that date as the dividing line: a user who installed the app afterwards, or who only ever signed with a hardware device, is told no action is needed. The public release notes for 8.1.0 describe multi-wallet support, wallet imports and wallet deletion. They mention no security fix.
The report deliberately leaves out the root cause, on the grounds that technical detail could be used in "identical or similar attacks." It gives no count of affected users and no loss figure. The FAQ says the minimum safe version is 10.0.0 and tells users not to transact from the App Wallet before updating. SlowMist's incident log records a $6.57 million loss, dated September 15. That entry predates most of the waves described below, and its method is marked unknown.
Six waves, one list
XRPL.to's account is the most detailed public record of what happened, and it is worth being clear about what kind of record it is. It is one analytics firm reading the public ledger. The firm revised it once already: its first version counted 1,548 wallets and 2,009,321 XRP on day one, figures picked up by several outlets, before it found the earlier by-hand sweeps.
This desk checked part of it independently. Querying a full-history XRP Ledger node, the first script collector, rDT8UP…wPui, shows a first incoming payment of 9.0 XRP and a total of about 1,278,000 XRP received in successful payments. That matches XRPL.to's two script batches of 19,416 and 1,258,632 XRP. The first by-hand collector, rh95U2…QDNb, still held 510,108.49 XRP when we checked.
The six waves, September 15 to 20 (UTC)
| Wave | Window | Wallets | XRP |
|---|---|---|---|
| 1 | Sep 15, 15:35–18:55 | 1,682 | 3,618,110 |
| D'CENT's first notice, Sep 16 | |||
| 2 | Sep 17 07:05 – Sep 18 01:28 | 814 | 2,725,737 |
| 3 | Sep 17 11:13 – Sep 18 07:53 | 130 swept, 111 deleted whole | 1,608,463 + 448,837 |
| 4 | Sep 18 11:02 – Sep 20 18:12 | 98 | 36,536 |
| 5 | Sep 18 15:14 – Sep 20 20:56 | 1,063 | 2,868,877 |
| 6 | Sep 19, 14:12–15:51 | 435 | 357,595 |
The day-one pattern suggests preparation. Every wallet above 42,001 XRP was moved by hand, and the eight largest went first, an hour before the script started. The script's first batch got the XRP Ledger's reserve rule wrong and failed on every wallet holding a trust line. After a 34-minute pause, during which the twelve richest remaining wallets were moved by hand, it came back with the arithmetic fixed. XRPL.to measured a rank correlation of 0.66 between the order in which batch two took wallets and their creation dates, and 0.10 against balance. In other words, the script was working through a prepared list sorted by when each wallet was made, not scanning the ledger for the biggest targets.
The later waves tie back to the first. Wave five was the day-one script, unchanged: the same 10-drop fee, and the reserve left behind to the drop on 1,061 of 1,067 sweeps. Wave six opened with the source tag and fee of the by-hand tool. From September 17, 1,283 of the wallets emptied on day one were deleted into wave three's collector.
The deletions are the tell
That last detail matters more than the totals. On the XRP Ledger, an AccountDelete transaction removes an account and sends its remaining reserve elsewhere, and only the account's own key can sign it. A user tricked into approving one bad payment would not produce this. By XRPL.to's count, the operator deleted 5,001 accounts, including 2,470 that had never been swept, one of them holding 107,507 XRP. Whoever did this held signing keys for thousands of wallets and could use them repeatedly over six days.
That fits D'CENT's own framing, a vulnerability in signing, and its advice to abandon the phrase entirely rather than just update the app. It does not tell anyone what the flaw was. XRPL.to also published a teardown of the Android app finding that the App Wallet's software signer approves whatever hash its web-based screen sends, with only a PIN and no display of the transaction. But that teardown examined version 9.2.1, later than D'CENT's 8.1.0 cutoff, and XRPL.to says itself that reading the app cannot establish what caused the transfers. They are two separate findings, and neither one explains the other yet.
Where it went
By XRPL.to's tally, 5,594,530 XRP was swapped to Ethereum through THORChain, 3,241,519 went to the exchange unionchain.ai, 546,080 to NEAR Intents and 535,666 to Binance deposit tags. As of the morning of September 21, 1,308,291 XRP remained in the operator's wallets. D'CENT says it is working with law enforcement, mainnet operators and exchanges to trace and freeze funds. On reimbursement, XRPL.to quotes a D'CENT reply from early September 21 saying the company does not yet have "a confirmed outcome" to share.
For anyone who has used the D'CENT app: the question is not whether you own a D'CENT device. It is whether a recovery phrase was ever entered into the App Wallet and used to sign on a version before 8.1.0. If so, D'CENT's guidance is to update to 10.0.0 or later, move the assets to a wallet made from a fresh recovery phrase, and stop using the old one. Hardware-only users who never typed their phrase into the app are outside the scope D'CENT describes.
The Take
D'CENT deserves credit for one thing: its version cutoff is specific enough for a user to check, which is more than most wallet incident notices offer. What it has not explained is the gap between that notice and what happened next. The ledger shows an operator who already had the keys and a sorted list before the first payment moved. That operator kept coming back for five days after the warning, when most of the value was taken. A notice that tells people to move their funds is a race, and the only way to win it is to reach them faster. Withholding the root cause to avoid giving copycats a manual is defensible. It is harder to defend a notice that went out the day after the drain began, with no affected-user count, no loss figure, no timeline for compensation, and no explanation of why a flaw apparently closed in November 2025 was still costing people money in September 2026.