D'CENT App Wallet Key Compromise
Attackers used compromised recovery phrases to sweep roughly 11.7 million XRP — about $18 million — from over 6,600 D'CENT App Wallet accounts across five chains.
- Date
- Victim
- D'CENT Wallet
- Status
- Funds Stolen
On September 15, 2026, users of D'CENT began losing funds as attackers swept roughly 11.7 million XRP — approximately $18 million — from more than 6,600 accounts of the company's software App Wallet, in an incident that spilled across five blockchains.
What happened
D'CENT sells a certified hardware wallet and, separately, a software App Wallet for phones. The attacker already held valid private keys or recovery phrases for thousands of App Wallet accounts, and drained them directly rather than by breaking any blockchain's consensus. Analysts tied the exposure to the App Wallet's key handling in versions before 8.1.0; the hardware wallets were not affected.
The theft ran in at least six waves between September 15 and 20. The thief hit the largest wallets first, by hand, then wrote scripts to empty progressively smaller ones. Because a single seed phrase controls addresses on many chains, the same compromised credential let the attacker sweep not only the XRP Ledger but also Bitcoin, Ethereum, Tron and Stellar. Roughly 6.3 million of the stolen XRP was bridged to Ethereum via THORChain to obscure the trail.
Aftermath
D'CENT urged every App Wallet user to generate a fresh recovery phrase and migrate all assets — tokens, NFTs and staked positions — immediately. A further 640,370 XRP was taken in a later wave after September 21. At roughly 11.7 million XRP, the incident ranked as the second-largest XRP theft of 2026, behind only the Bitget exchange breach. No recovery had been reported as of writing.
Why it matters
A single compromised seed phrase draining five chains at once is the defining risk of multichain software wallets: the credential is the asset, and its blast radius is every chain it derives. The contrast with D'CENT's untouched hardware line — and with dedicated signing devices like Coldcard — underlines why high-value holders keep keys off internet-connected software. It also shows how deterministic, multichain seed derivation turns one leak into a cross-chain sweep before victims can react.
Sources & on-chain evidence
- [01]protos.comhttps://protos.com/the-years-second-largest-xrp-hack-is-spilling-over-to-bitcoin-and-ethereum/
- [02]cryptotimes.iohttps://www.cryptotimes.io/2026/09/21/crypto-hacks-drain-20m-this-week-rseth-safe-nostra-fall/
- [03]thecryptobasic.comhttps://thecryptobasic.com/2026/09/17/heres-how-the-dcent-wallet-hacker-drained-2-million-xrp-in-two-hours/