Hackers made off with approximately 11.7 million XRP from thousands of users of the D’CENT App Wallet. The heist, valued at nearly $20 million, took place between September 15 and 20, according to an on-chain forensic timeline detailed by XRPL.to.
The entire operation transpired across six distinct waves, impacting a total of 6,678 wallets utilizing private keys that were already in the possession of the thief.
How the Attack Actually Unfolded
Within a single hour on September 15, an individual manually emptied eight separate wallets, with each holding in excess of 99,999 XRP. Later that same day, an automated script drained another 1,682 wallets.
Five additional waves took place through September 20, with every wave consistently employing the identical manual tool, script, and stolen keys.
As XRPL.to pointed out, the perpetrators went beyond straightforward token transfers by completely deleting 5,001 accounts to collect their leftover reserve balances.
Significantly, 2,470 of those specific wallets had never even been swept, indicating that the thief possessed a larger roster of compromised keys than what the initial wave of drains showed.
The plundered assets were transferred rapidly. Around 5.6 million XRP were bridged to Ethereum via THORChain, while remaining funds passed through crypto exchanges like Binance, alongside platforms such as NEAR Intents and unionchain.ai.
Because each sweep typically hit an off-ramp within a matter of hours, the window to freeze any stolen assets was severely restricted. By September 21, roughly 1.3 million XRP remained held inside the attacker’s own wallets.
Why Are D’CENT Users Specifically at Risk?
D’CENT acknowledged irregular transfers impacting its App Wallet on September 16, while emphasizing that its hardware wallets were completely unaffected. The company subsequently advised users to transfer their funds away right away, though it has not yet stated whether it will provide refunds.
Crucially, the incident did not stem from any security breach within the XRP Ledger. Because every single sweep executed with legitimate signatures generated from the wallets’ private keys, the vulnerability originated from the exposure of those keys rather than a network-level flaw.
5.6 Million XRP Moved to Ethereum Through THORChain. Source: xrpl.to
XRPL.to noted that the attack exhibited consistent scripts and fee behavior across all waves, pointing to a single unified perpetrator behind the entire campaign. Consequently, security experts are advising a vital precaution.
Anyone who has utilized the D’CENT App Wallet is strongly advised to transfer their assets to a brand-new wallet without delay. The exact mechanism responsible for the initial key exposure remains undetermined.
At the time of publication, XRP was changing hands around $1.49, representing a 6% decline over a 24-hour period based on BeInCrypto figures. The cryptocurrency boasted a market valuation of about $93.82 billion, holding the fifth-largest spot globally.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights.
Frequently Asked Questions
How much XRP was stolen in the attack?
Attackers drained roughly 11.7 million XRP, which translates to a value close to $20 million.
Were D’CENT hardware wallets affected?
No, D’CENT confirmed that its hardware wallets remained unaffected, and that the abnormal transfers only impacted its App Wallet.
What caused the vulnerability on the XRP Ledger?
There was no exploit or flaw in the XRP Ledger itself. Every sweep used valid signatures from the affected wallets’ own private keys, meaning the issue stemmed from how those keys were exposed.
Where did the stolen funds go?
About 5.6 million XRP crossed into Ethereum through THORChain, while other funds were routed through exchanges like Binance and services such as unionchain.ai and NEAR Intents.
What should D’CENT App Wallet users do now?
Security researchers recommend that anyone who used the D’CENT App Wallet at any point should immediately migrate their funds to a new wallet.


