Compromised private keys, six waves of theft, and over half the funds already laundered through THORChain.

Here's what happened and what to do if you're affected.

🚨 On September 15, attackers drained around 3.6 million XRP from 1,682 wallets in under three hours. That speed alone tells you something, this wasn't a real-time exploit someone discovered and rushed to use. The access had almost certainly been sitting there for a while before anyone touched it.

Ten days later, the total had climbed to more than 12.4 million XRP stolen from over 7,393 D'CENT App Wallet users, worth somewhere in the $18-20 million range depending on the price used at the time of each theft.

🔓 So what actually broke?

The compromise traces back to how private keys were handled in older versions of the D'CENT app, specifically versions before 8.1.0, which was released back in November 2025. If you never updated past that version, or updated late, your keys may have already been exposed before you even knew there was a problem. This is different from a hardware wallet compromise. D'CENT's hardware secure element itself wasn't broken; the vulnerability sat in the app layer.

📉 The theft didn't stop after the first wave, and that's the part worth sitting with.

Warnings went out from D'CENT and members of the XRP community during this period. They didn't stop it. More than 640,000 additional XRP was stolen after September 21, days after the alerts were already circulating. That gap, between "people were warned" and "people kept losing funds", usually comes down to one of two things: some users never saw the warning, or the attacker had already automated the draining process before anyone could react manually.

🔀 Once the XRP left D'CENT wallets, it didn't stay there.

Roughly half the stolen funds have already been swapped from XRP to Ethereum through THORChain, the same cross-chain protocol used to launder a large share of the recent Bitget exchange hack. If you read our earlier piece on Bitget, this is the identical playbook: steal funds, move them fast through a protocol that doesn't require identification, and convert them into a different asset before anyone can meaningfully trace or freeze them. As of the most recent reporting, roughly 1.4 million XRP was still sitting in known attacker-controlled addresses, meaning some activity may still be ongoing.

🧠 Why does this matter beyond D'CENT specifically?

Because the pattern here isn't unique to one wallet provider. App-layer key handling bugs are a different, and in some ways scarier, category of risk than a smart contract exploit or an exchange breach. Users did everything "right" in the traditional sense, they used a wallet with a hardware secure element instead of leaving funds on an exchange, and they were still exposed because the vulnerability lived somewhere they had no way to inspect themselves.

✅ What this means for you

If you use or have ever used a D'CENT App Wallet, stop using it immediately if you're still on an old version, and do not reuse any recovery phrase that was ever entered into a compromised app version, even in a different wallet. Move remaining assets to a newly generated address created in a trusted, updated wallet environment. Reusing an exposed seed phrase anywhere just recreates the same risk somewhere else.

If you don't use D'CENT, this is still a useful prompt to check when you last updated any wallet app you rely on, hardware or software. A hardware wallet's secure element protects your keys from certain attacks, but it doesn't protect you from a vulnerability in the companion app that manages those keys.

If you're tracking stolen-fund movement generally, this is another real-world data point on THORChain's role in laundering stolen crypto, following directly on from the Bitget case. Worth watching whether that draws the same kind of scrutiny from security researchers that the Bitget/THORChain situation did.

🟡 What would limit further damage
D'CENT users who haven't yet migrated do so quickly, remaining attacker-controlled funds get flagged and frozen before further laundering, and exchanges tighten monitoring on addresses tied to this specific attack.

🔴 What would make it worse
More affected users remain unaware and keep using compromised app versions, the remaining 1.4 million XRP gets fully laundered before it can be traced, and this pattern repeats on another wallet provider before the industry adapts.

👀 Three things to watch

1️⃣ D'CENT's official disclosure
Does the company publish a full technical post-mortem explaining exactly how the key compromise happened, or does the mechanism stay unexplained?

2️⃣ The remaining funds
Does the roughly 1.4 million XRP still in attacker-controlled addresses get frozen or traced, or does it fully exit through THORChain like the rest?

3️⃣ Whether other wallet providers are affected
Does this turn out to be isolated to D'CENT, or do similar app-layer vulnerabilities surface elsewhere in the coming weeks?

💡 The key takeaway

This wasn't a smart contract exploit or an exchange breach. It was a slower-burning, app-level key compromise that let attackers drain wallets in waves over ten days, even after warnings were already public.

The real question is whether D'CENT's disclosure ends up giving the industry a clear enough picture to prevent the same mistake elsewhere, or whether this becomes one more case where the full technical cause never gets fully explained.

That is the part worth watching.

This post is for informational and educational purposes only and is not financial advice. Crypto markets are volatile. Always conduct your own research before making financial decisions.

#BinanceSquare #XRP #CryptoSecurity #Hack #THORChain

XRP
XRP
1.4892
-0.31%