A mobile app for a hardware wallet brand was stolen, and in 10 days, 12.4 million $XRP were taken.
​
What happened involves D'CENT’s wallet app. From 9/15 to 9/25, a total of 7,393 wallets were drained, including 6,095 accounts that were entirely deleted.
​
The first wave was the most severe: in under 3 hours on 9/15, about 3.6 million XRP were transferred out from 1,682 wallets. After 9/21, more thefts continued, taking another 640,000+ XRP.
​
The suspected root cause points to private key handling. Affected are old versions of the app prior to 8.1.0—that is, versions released before November 2025.
​
The vendor has not yet disclosed the specific mechanism, but it has been confirmed to be a software issue, not a hardware/firmware problem.
​
About half of the stolen XRP has already been laundered. The path was to convert it via THORChain into Ethereum, then split and route the funds out to multiple destinations.
​
According to guidance from the vendor and security teams: any mnemonic phrase used in the old app version should be considered compromised, and you should not send funds to the old addresses anymore.
​
This is the second-largest XRP theft incident this year. Reports have already mentioned that the same batch of mnemonic phrases also showed abnormal outgoing transfers on BTC and ETH.
​
If the software app of a hardware wallet brand is compromised, will it lead people to redraw the security boundaries of “cold wallets”?