A massive security incident has shaken the XRP community after on-chain tracking revealed that nearly $20 million worth of $XRP (approx. 11.75M XRP) was systematically drained from thousands of non-custodial software and hardware wallets. Operated by South Korean security firm IoTrust, the D’CENT Wallet ecosystem experienced six distinct waves of unauthorized draining transactions between September 15 and September 20.

The breach has prompted urgent security warnings across the crypto space as investigators work to determine how signing keys were exposed.

1. Six Waves of Exploits Drain 6,678 Wallets

Blockchain analytics firm XRPL.to identified that the drainers executed validly signed transactions across 6,678 individual wallet addresses. The attacks were executed using two primary methods:

  • Payment Sweeps: Over 4,200 wallets were drained via standard payment transfers.

  • Account Deletions: Nearly 2,500 addresses were completely wiped out using the XRP Ledger’s AccountDelete function, allowing attackers to claim the base account reserve balances that ordinary sweeps leave behind.

Subsequent tracking showed that over 5.6 million XRP was immediately routed through cross-chain protocols like THORChain, NEAR Intents, and centralized exchange deposit addresses to obscure the money trail.

2. Root Cause & App Version Vulnerability

Preliminary findings indicate that the vulnerability stems from older versions of the D’CENT mobile App Wallet:

[Legacy App Key Exposure] ──> [Validly Signed Sweeps] ──> [Cross-Chain Laundering]

  • Vulnerable Versions: Users who entered or restored their seed phrases in D’CENT App Wallet versions prior to v8.1.0 (released Nov 5, 2025) are at high risk.

  • Hardware Wallet Impact: Standalone D’CENT hardware wallets remain secure unless their recovery phrase was previously entered into the mobile software app.

  • Crucial Action: Updating the app alone is not sufficient. Users must generate an entirely new recovery phrase on a clean wallet and migrate all remaining assets immediately.

3. Law Enforcement Involvement & Recovery Process

IoTrust has engaged Korean law enforcement cyber-crime units, security specialists, and major exchanges to attempt asset freezes. However, due to the rapid cross-chain movement through decentralized protocols, no completed recoveries have been confirmed yet.

D’CENT has issued warnings regarding secondary scam attempts, reminding users that team members will never request private keys, seed phrases, or ask for assets to be sent to "recovery addresses".

Essential Financial Disclaimer

This article is provided strictly for educational, news, and informational purposes only. Non-custodial storage, smart contracts, and digital asset wallets carry inherent technical risks, including potential key compromise and software vulnerabilities. Nothing contained herein constitutes financial, legal, or investment advice. Always perform independent security reviews (DYOR) and follow official security guidelines from wallet providers.

📢 Is your wallet secure? Don't take chances with self-custody security vulnerabilities!