Advertisement

The technology behind this newsroom. Built by Cyntri AI.

AI-assisted publishing and analytics. This site is our working example.

Hack Database

D'CENT: $16M in XRP Drained From 6,678 Wallets by a Bug Fixed Ten Months Earlier

Thieves emptied 6,678 D'CENT phone wallets of 11.75 million XRP, about $16M, through a flaw in app versions older than November 2025.

D'CENT: $16M in XRP Drained From 6,678 Wallets by a Bug Fixed Ten Months EarlierLogos: DCENT, XRP Ledger
Thieves emptied thousands of DCENT app wallets holding XRP.

Key numbers

  • $16M

    Stolen

  • 11.75M

    XRP taken

  • 6,678

    Wallets emptied

  • Unidentified

    Attacker

At 15:35 UTC on 15 September 2026, just after half past midnight in Seoul, someone began emptying XRP accounts belonging to customers of D'CENT, a South Korean wallet maker. The first eight accounts each held more than 99,999 XRP, and they were drained by hand. Then a script took over. Within hours, 1,682 accounts were empty.

A crypto wallet is where people keep digital money, roughly what a brokerage account is to shares, except that there is no broker. Whoever holds the account's secret key owns what is in it. D'CENT, which dropped its apostrophe and became DCENT on 8 September, is made by IoTrust, a Seoul company founded in 2017 by chip-security engineers and run by chief executive Baek Sang-su. It is best known for a fingerprint-locked hardware wallet, a small device that keeps the key away from the internet. The emptied accounts were not on those devices. They lived in the DCENT App Wallet, the phone app, where the key sits on the phone itself.

The thief came back five more times. By 20 September, XRPL.to, an analytics site that tracks the XRP Ledger (the public record of every XRP payment), counted 11,746,198 XRP taken from 6,678 accounts. At CoinGecko's daily prices for the days of the thefts, that was roughly $16 million. At the $1.59 price of 23 September, when CryptoSlate published the count, it was $18.7 million. A later tally reported by Crypto Briefing on 25 September reached about 12.4 million XRP from 7,393 wallets. The security firm SlowMist logged a much lower $6.57 million on its public tracker, and DCENT has published no figure at all. Losses in Bitcoin, Tether, Tron and Stellar are not in any of these totals.

Advertisement

Live DeFi agents

Watch four AI agents manage money in public.

Stablecoins across Base, Arbitrum, Optimism, Polygon and Avalanche. Every decision is on-chain.

Subscription opening soon. Not financial advice.

  • BASE
  • ARB
  • OP
  • POL
  • AVAX

XRP is a digital currency closely tied to the American payments company Ripple, and it has a devoted following in South Korea. About a quarter of the drained accounts had been funded from the Korean exchanges Upbit, Bithumb and Coinone, according to XRPL.to's analysis as reported by the news site Blockhead. DCENT's own website carried a banner that read "Made for XRP holders".

Fixed in November, drained in September

The one thing DCENT has been clear about is who is at risk. In a status report dated 17 September, the company said the danger applies to any address whose recovery phrase was ever typed into the App Wallet and which signed a transaction in an app version older than 8.1.0. A recovery phrase is the list of 12 or 24 words that rebuilds a wallet from scratch: the master key to everything inside. Signing is how a wallet approves a payment, the digital version of signing a cheque. Version 8.1.0 was released on 5 November 2025.

That date is the uncomfortable part. Signatures made on 8.1.0 or later are outside the danger zone, so whatever changed in that release appears to have closed the hole. But DCENT's public announcement of 8.1.0, issued on 10 November 2025, was about managing up to 100 wallets and importing accounts from MetaMask and Phantom. It said nothing about security. DCENT has not said whether it knew the update fixed a flaw. Its warning to move money came on 16 September 2026, hours after the thefts began, ten months after the update.

How it worked

DCENT has refused to publish the technical cause, saying the details could help copycats. The shape of its warning still says a lot. Addresses that had only ever received money were at "comparatively lower" risk. Addresses that had signed anything, including a token approval or a connection to an online service, were at risk. That points away from stolen passwords and towards the signatures themselves.

Every digital signature mixes the secret key with a fresh random number, used once and thrown away. If that number is predictable, or repeats, the maths behind the signature can be run backwards, much like solving two simultaneous equations, and the key falls out. The signatures sit on the public ledger for anyone to read. An attacker who knows how a faulty app picked its numbers can collect signatures and calculate keys at leisure.

Oh Hyun-ok, a professor at Hanyang University, told ZDNet Korea the likeliest suspect was that the old app did not use enough randomness when creating recovery phrases or signing transactions. Hwang Seok-jin of Dongguk University pointed investigators at the same area while saying phishing could not be ruled out. There is a precedent. In August 2013, a flaw in Android's random number generator let thieves pull private keys out of bitcoin signatures made by several wallet apps. DCENT says the first irregular transactions this time were seen on Android, though the same risk applies to iPhones.

The theft looked like someone working through a list. XRPL.to found that accounts were drained in an order that followed when they were created, mostly between 2021 and 2023, far more closely than how much they held. Every transfer carried a valid signature from the account's own key. Nothing in the XRP Ledger itself was broken. The thief simply had the keys.

The XRP Ledger makes every account lock up a small deposit, called a reserve, just to exist. To collect those deposits too, the thief deleted accounts after emptying them: 5,001 deletions in the first six days, according to XRPL.to, including one account opened in 2022 that still held 107,507 XRP.

Where the money went

Speed was the point. XRPL.to traced about 5.59 million XRP through THORChain, a service that swaps one cryptocurrency for another across separate blockchains without asking who the customer is, and on into Ethereum. About 3.24 million XRP went to unionchain.ai, 546,080 to NEAR Intents, another cross-chain swap service, and 535,666 to deposit addresses at Binance, the largest crypto exchange by trading volume. About 1.31 million XRP still sat in wallets linked to the operation on 21 September.

Bar chart of where 11.75 million stolen XRP went: 5.59M through THORChain to Ethereum, 3.24M to unionchain.ai, 1.31M still in attacker wallets, 0.55M NEAR Intents, 0.54M BinanceCMZ chart. Data: XRPL.to
Where the stolen XRP went.

The alarm did not stop the draining. Korean press reports on XRPL.to's data counted 7,597,207 XRP taken from 2,532 accounts after DCENT's warning on 16 September. On 23 September one holder lost 72,521 XRP, then 2,488 more half an hour later, plus 17,244 Stellar lumens: more than $120,000 in total, according to The Crypto Basic. The lumens reached the exchange Changelly within about four hours.

Who pays

IoTrust told ZDNet Korea it had received 110 reports from victims by 18 September and had asked police and exchanges to freeze stolen funds. On 22 September it gave its own analysis to KISA, the Korea Internet and Security Agency, and asked the government body to issue a cyber-threat alert. Its status report says any freezing or recovery depends on authorities and third parties. No compensation has been offered.

On 8 September, a week before the first theft, DCENT celebrated its new name with a blog post saying that across eight years it had had "zero security breaches". It was talking about its hardware. DCENT says the hardware is still unaffected.

The aftermath

As of 28 September 2026, DCENT had not published a loss figure, a technical cause or a compensation plan. Its status report of 17 September remained the latest update on its blog. The company says it is working with Korean law enforcement, exchanges, blockchain foundations and an outside security team to trace and freeze funds, and that recovery depends on the authorities and third parties. No freeze or arrest has been announced, and nobody has been publicly identified as the attacker.

The estimates still disagree. XRPL.to's count of 11,746,198 XRP from 6,678 accounts to 20 September is the most widely cited, and Korean outlets put it at more than 20 billion won. Crypto Briefing's later figure of about 12.4 million XRP from 7,393 wallets covers thefts up to 25 September, including more than 640,000 XRP taken after 21 September. SlowMist's tracker shows $6.57 million. None of these includes the Bitcoin, Tether, Tron and Stellar also taken. Crypto Briefing reported that about 6.3 million XRP had already been laundered and 1.4 million remained in attacker addresses on 25 September.

The draining left a mark on the XRP Ledger itself. On 24 September the network recorded 11,610 new accounts, its highest daily figure since February, and 1,159 account deletions; The Crypto Basic linked both spikes to the attacker creating collection wallets and deleting emptied ones.

IoTrust asked KISA on 22 September for a national cyber-threat alert and shared its analysis so the agency could check whether other wallets were exposed; Korean reports said no identical damage had been found elsewhere. DCENT's instructions to users are to update to app version 10.0.0 or later, create a brand-new recovery phrase, move every coin, token and NFT to the new address, and never reuse the old phrase, because restoring it would recreate the same compromised key. It has also warned of impersonation accounts offering "recovery" to victims.

What this teaches

  • A software update that quietly closes a hole does nothing for keys that were already exposed. Users have to be told to move their money, and here that warning came ten months after the update.
  • Signing can leak a key as surely as creating it. If the one-time random number in each signature is weak, every past payment becomes evidence an attacker can mine.
  • A hardware wallet is only as safe as every place its recovery phrase has ever been typed. DCENT hardware owners who restored their words into the phone app were in scope.
  • Cross-chain swap services such as THORChain and NEAR Intents moved millions within hours, which is why freezes in cases like this are rare.
  • A company that will not publish the cause leaves users unable to judge their own risk; 'comparatively lower' is not the same as safe.
Advertisement

Free AI assistant

AI that works, and proves it.

Ask Cynt how AI could help your business. Free to try.

Free AI assistant