D'CENT Wallet Hack: Nearly $20M in XRP Stolen From 6,678 Wallets

2026-09-24
D'CENT Wallet Hack: Nearly $20M in XRP Stolen From 6,678 Wallets

The D'CENT Wallet Hack drained nearly $20 million in XRP from 6,678 wallets between September 15 and September 20, 2026, as attackers stole roughly 11.7 million XRP from D'CENT App Wallet users in six coordinated waves using compromised private keys.

This article breaks down exactly what happened, how the attack unfolded wave by wave, what D'CENT has said, and what any XRP holder should do to protect their wallet going forward.

Key Takeaways

  • Attackers stole roughly 11.7 million XRP, worth close to $20 million, from 6,678 D'CENT App Wallet users across six coordinated waves between September 15 and 20, 2026.

  • Every transaction used valid signatures from the wallets' own private keys, meaning the theft stemmed from exposed keys rather than any flaw in the XRP Ledger itself.

  • D'CENT confirmed hardware wallets were unaffected; only the software-based App Wallet was compromised, and the company has urged affected users to move funds immediately.

What Happened in the D'CENT XRP Hack

On-chain forensics firm XRPL.to reconstructed the timeline in detail, and it reads like a methodical operation rather than a single smash-and-grab. On September 15, someone manually drained eight wallets, each holding more than 99,999 XRP, within the span of an hour. 

That same day, an automated script swept a much larger batch: 1,682 wallets in total. Five more waves followed over the next several days, each one reusing the same script, the same manual tooling, and the same set of compromised keys.

What Happened in the D'CENT XRP Hack.jpg
Ai Generated

The attacker didn't stop at transferring funds out. In a number of cases, they deleted the wallet accounts entirely, a move on the XRP Ledger that reclaims a small reserve balance locked into every active account. XRPL.to counted 5,001 deleted accounts in total, and notably, 2,470 of those had never actually been swept for their main balance before being deleted. 

That detail matters: it suggests the attacker was working from a broader list of compromised keys than what the drains alone revealed, closing out empty or low-value accounts simply to collect leftover reserves.

How 11.7 Million XRP Left So Many Wallets So Fast

Once funds were pulled from a wallet, they didn't sit still. Roughly 5.6 million XRP moved across to Ethereum through THORChain, a cross-chain liquidity protocol, while other portions were routed through centralized exchanges including Binance, as well as services like unionchain.ai and NEAR Intents. 

Each wave of theft often reached an off-ramp within hours of the initial drain, which sharply limited the window available for exchanges or investigators to freeze anything. As of September 21, an estimated 1.3 million XRP was still sitting in wallets under the attacker's direct control, not yet moved further.

One especially important technical detail here: every single sweep used valid signatures generated from the wallets' own private keys. 

There was no XRP Ledger exploit involved. The compromise happened somewhere upstream, in how those private keys were generated, stored, or exposed in the first place, not in any weakness in the network processing the transactions.

Keep your crypto safer after incidents like this! Register on Bitrue to trade supported assets with strong security features and stay in control of your funds.

D'CENT's Response and What It Confirmed

D'CENT confirmed abnormal transfer activity affecting its App Wallet on September 16, a day after the first wave of drains began. Crucially, the company clarified that its hardware wallets were not affected, isolating the exposure to the software-based App Wallet specifically.

D'CENT has urged affected users to move their remaining funds immediately, though as of this writing it hasn't confirmed whether any form of reimbursement will follow.

D'CENT's own support documentation, published before this incident, lays out the wallet's basic security model and is worth understanding in this context. 

The App Wallet, like the rest of D'CENT's product line, is non-custodial, meaning D'CENT itself doesn't store recovery phrases, PINs, or other private credentials on its servers. That's standard practice for a self-custody wallet, but it also means the company has stated plainly that it cannot recover assets lost through a key compromise. 

Its guidance for anyone who suspects their wallet has been compromised centers on a few core steps: move any remaining assets to a new, secure wallet address immediately, check whether a recovery phrase was ever photographed, typed into an unverified site, or stored in cloud services, and review whether the wallet was ever connected to a phishing site or an unverified decentralized app.

Why This Points to a Wallet-Level Compromise, Not an XRP Flaw

It's worth being precise about what this incident is and isn't. XRP as a network wasn't hacked, and the XRP Ledger's core protocol functioned exactly as designed throughout the entire episode. Every transaction that drained a wallet carried a legitimate cryptographic signature, which only an attacker in possession of that wallet's private key or recovery phrase could produce. 

That distinction is the difference between a protocol-level vulnerability, which would be catastrophic and affect the entire XRP ecosystem, and a wallet-level or application-level compromise, which is serious but contained to the users of one specific product.

XRPL.to's analysis also found that the operation reused identical scripts and fee patterns across every wave, which strongly points to a single coordinated actor rather than multiple unrelated attackers exploiting the same weakness independently.

join bitrue to get 938 usdt

XRP Wallet Security: What to Do If You Used D'CENT's App Wallet

If you've ever used D'CENT's App Wallet, security researchers and D'CENT itself agree on the same immediate step: migrate any remaining funds to a brand-new wallet with a freshly generated recovery phrase, on a device you trust. A compromised recovery phrase is compromised permanently. 

Moving funds to a new address that was derived from the same old phrase does nothing, because the attacker still holds the master key to every address that phrase can generate.

A few broader habits reduce exposure to this kind of incident regardless of which wallet you use. Never enter a full recovery phrase into a website, app, or messaging platform, and be especially wary of anything claiming to be D'CENT customer support asking for that information, since the company has stated it will never ask for recovery words, PINs, or private credentials. 

Avoid photographing or screenshotting a recovery phrase, and don't store it in notes apps, cloud storage, or email. Review and revoke any token approvals granted to decentralized apps you no longer use or don't recognize. And where practical, keep balances that aren't being actively used off hot, internet-connected wallets entirely.

Read also: D’CENT Wallet Unveils GasPass for Free Crypto Transfers!

Summary

The D'CENT wallet hack is a reminder that the most damaging crypto losses rarely come from a broken blockchain. They come from compromised keys, and once a key is exposed, no amount of moving funds around within the same compromised wallet actually fixes the problem. In this case, a methodical, six-wave operation drained 11.7 million XRP from 6,678 App Wallet users over five days, moving stolen funds through THORChain and multiple exchanges faster than they could realistically be frozen. 

D'CENT has isolated the exposure to its software wallet, confirmed hardware wallets are safe, and pointed affected users toward migrating to newly generated wallets immediately. For anyone holding XRP or any other asset in a software wallet, this incident is a strong argument for treating recovery phrases with the same seriousness as a bank vault combination.

Disclaimer: The views expressed belong exclusively to the author and do not reflect the views of this platform. This platform and its affiliates disclaim any responsibility for the accuracy or suitability of the information provided. It is for informational purposes only and not intended as financial or investment advice.

FAQ

What is the D'CENT wallet hack?

It's a security incident where attackers drained roughly 11.7 million XRP, worth close to $20 million, from 6,678 users of D'CENT's App Wallet across six waves between September 15 and 20, 2026, using private keys they had already compromised.

Was the XRP Ledger itself hacked?

No. Every transaction in this incident used valid signatures from the wallets' own private keys, meaning the exploit occurred at the wallet or key-management level, not within the XRP Ledger's protocol itself.

Were D'CENT hardware wallets affected?

No. D'CENT confirmed that only its software-based App Wallet was affected. Hardware wallets were not impacted by this incident.

How much XRP was stolen and from how many wallets?

Attackers stole approximately 11.7 million XRP, worth close to $20 million at the time, from 6,678 wallets across six separate attack waves.

What should D'CENT App Wallet users do now?

Anyone who has used D'CENT's App Wallet should move any remaining funds to a newly generated wallet on a trusted device immediately, and treat any previously used recovery phrase as permanently compromised.

Disclaimer: The views expressed belong exclusively to the author and do not reflect the views of this platform. This platform and its affiliates disclaim any responsibility for the accuracy or suitability of the information provided. It is for informational purposes only and not intended as financial or investment advice.

Disclaimer: The content of this article does not constitute financial or investment advice.

Register now to claim a 6752 USDT newcomer's gift package

Join Bitrue for exclusive rewards

Register Now
register

Recommended

Russia's Digital Ruble: Limits, Rules, and How It Works
Russia's Digital Ruble: Limits, Rules, and How It Works

Russia’s digital ruble is a CBDC with a 300,000-ruble monthly transfer cap, phased merchant rules from 2026–2028, free transfers, offline payments, and no interest. Learn limits, business requirements, and how the central bank platform works.

2026-09-24Read