A mobile app for a hardware wallet brand was stolen, and in 10 days, 12.4 million $XRP were taken.
What happened involves D'CENT’s wallet app. From 9/15 to 9/25, a total of 7,393 wallets were drained, including 6,095 accounts that were entirely deleted.
The first wave was the most severe: in under 3 hours on 9/15, about 3.6 million XRP were transferred out from 1,682 wallets. After 9/21, more thefts continued, taking another 640,000+ XRP.
The suspected root cause points to private key handling. Affected are old versions of the app prior to 8.1.0—that is, versions released before November 2025.
The vendor has not yet disclosed the specific mechanism, but it has been confirmed to be a software issue, not a hardware/firmware problem.
About half of the stolen XRP has already been laundered. The path was to convert it via THORChain into Ethereum, then split and route the funds out to multiple destinations.
According to guidance from the vendor and security teams: any mnemonic phrase used in the old app version should be considered compromised, and you should not send funds to the old addresses anymore.
This is the second-largest XRP theft incident this year. Reports have already mentioned that the same batch of mnemonic phrases also showed abnormal outgoing transfers on BTC and ETH.
If the software app of a hardware wallet brand is compromised, will it lead people to redraw the security boundaries of “cold wallets”?
What happened involves D'CENT’s wallet app. From 9/15 to 9/25, a total of 7,393 wallets were drained, including 6,095 accounts that were entirely deleted.
The first wave was the most severe: in under 3 hours on 9/15, about 3.6 million XRP were transferred out from 1,682 wallets. After 9/21, more thefts continued, taking another 640,000+ XRP.
The suspected root cause points to private key handling. Affected are old versions of the app prior to 8.1.0—that is, versions released before November 2025.
The vendor has not yet disclosed the specific mechanism, but it has been confirmed to be a software issue, not a hardware/firmware problem.
About half of the stolen XRP has already been laundered. The path was to convert it via THORChain into Ethereum, then split and route the funds out to multiple destinations.
According to guidance from the vendor and security teams: any mnemonic phrase used in the old app version should be considered compromised, and you should not send funds to the old addresses anymore.
This is the second-largest XRP theft incident this year. Reports have already mentioned that the same batch of mnemonic phrases also showed abnormal outgoing transfers on BTC and ETH.
If the software app of a hardware wallet brand is compromised, will it lead people to redraw the security boundaries of “cold wallets”?
