Attackers drained roughly 12.4 million XRP from 7,393 D'CENT App Wallet users over a 10-day spree, exploiting compromised private keys in app versions older than 8.1.0. More than half the stolen funds have already moved through THORChain into Ethereum and onward to exchanges, while about 1.4 million XRP still sits in attacker-controlled addresses.
A security breach targeting the D'CENT App Wallet drained roughly 12.4 million XRP from 7,393 wallets, with attackers exploiting compromised private keys over a 10-day window running from September 15 to September 25. The theft came in waves, and roughly half the haul has already moved through cross-chain swaps.
The first wave hit hardest
On September 15, attackers drained around 3.6 million XRP from 1,682 wallets in under three hours, using a mix of manual and automated methods. That speed suggests the access was pre-positioned rather than exploited in real time, meaning the key compromise likely predated the theft itself.
Users began flagging suspicious activity on September 16, a day after the first wave. On-chain analysis tied the unauthorized transfers to D'CENT App Wallet versions older than 8.1.0, released on November 5, 2025. D'CENT has not fully disclosed the mechanism behind the key compromise. Hardware wallet users were not affected unless they had imported their recovery seed phrase into the compromised app, since the attack vector was software-side rather than a firmware flaw.
The bleeding continued past the warnings
Even after public warnings circulated, more than 640,000 XRP was stolen after September 21, suggesting some users had not seen the alerts or that automated scripts kept running against wallets whose keys were already extracted. By the time on-chain observers tallied the damage, 6,095 accounts had been deleted entirely.
Following the laundering trail
Roughly 6.3 million XRP, just over half the total haul, has already been laundered. Attackers swapped the stolen XRP for Ethereum using THORChain, a cross-chain liquidity protocol that does not require user identification, then routed the funds to centralized exchanges including Binance.
As of September 25, approximately 1.4 million XRP remained in monitored attacker-controlled addresses, with activity still ongoing. D'CENT says it is working with law enforcement to trace and freeze the stolen funds, and has warned users not to send XRP to old wallet addresses or reuse recovery phrases ever entered into the compromised app versions.
Source: Crypto Briefing
Trading involves risk.