From September 15 to 25—ten days—D'CENT’s App Wallet was compromised, with 12.4 million XRP stolen, affecting 7,393 wallets, for about $20 million.
This is the second-largest XRP theft case this year—the first was Bitget’s 102.9 million XRP.
But one thing needs to be made clear first:
This is not a breach of a hardware wallet; it’s the leakage of the private key from the App Wallet (software version).
D'CENT has both hardware wallets and app wallets, and only the app version was affected this time—specifically users on versions before 8.1.0, if you entered a seed phrase in this version or signed any transactions.
The hacker’s path is very clear:
In the first wave on September 15, within three hours, they manually emptied 1,682 large wallets; then they wrote scripts to batch-empty wallets, shrinking in size; even after the announcement, it continued—because some users hadn’t seen the warning yet and because the scripts were still running.
An even more serious issue: a single seed phrase controls multiple chains.
When the same set of private keys was stolen, the losses spread from XRP to BTC, ETH, Tron, and Stellar—one key and everything went in.
The hacker used THORChain to cross-chain swap XRP for ETH, then routed it into exchanges such as Binance—by September 25, 6.3 million XRP had already been laundered.
If you’re using a D'CENT App Wallet and your version is before 8.1.0: don’t use this wallet anymore. Generate a new seed phrase using a completely new device, and transfer your assets out immediately.
This isn’t the first time, and it won’t be the last.
Where is your asset now?
$XRP
#黑客从dcent钱包盗取超1240万枚xrp
This is the second-largest XRP theft case this year—the first was Bitget’s 102.9 million XRP.
But one thing needs to be made clear first:
This is not a breach of a hardware wallet; it’s the leakage of the private key from the App Wallet (software version).
D'CENT has both hardware wallets and app wallets, and only the app version was affected this time—specifically users on versions before 8.1.0, if you entered a seed phrase in this version or signed any transactions.
The hacker’s path is very clear:
In the first wave on September 15, within three hours, they manually emptied 1,682 large wallets; then they wrote scripts to batch-empty wallets, shrinking in size; even after the announcement, it continued—because some users hadn’t seen the warning yet and because the scripts were still running.
An even more serious issue: a single seed phrase controls multiple chains.
When the same set of private keys was stolen, the losses spread from XRP to BTC, ETH, Tron, and Stellar—one key and everything went in.
The hacker used THORChain to cross-chain swap XRP for ETH, then routed it into exchanges such as Binance—by September 25, 6.3 million XRP had already been laundered.
If you’re using a D'CENT App Wallet and your version is before 8.1.0: don’t use this wallet anymore. Generate a new seed phrase using a completely new device, and transfer your assets out immediately.
This isn’t the first time, and it won’t be the last.
Where is your asset now?
$XRP
#黑客从dcent钱包盗取超1240万枚xrp

