Sat. Sep 26th, 2026

D’CENT XRP Drain Reaches 12.4M as Same Keys Keep Working Through Sept. 25

ByJohan Shamshad

September 26, 2026
HackHack

The XRP drain linked to D’CENT’s App Wallet has expanded to 12.4 million XRP across 7,393 wallets, with fresh on-chain analysis showing that the same operator, transaction tools and wallet keys continued to be used through September 25.

The latest reconstruction from XRPL.to puts the total at 12,402,589 XRP taken between September 15 and September 25. The tally includes conventional wallet sweeps as well as thousands of XRP Ledger account deletions carried out with valid account credentials.

The continued activity is significant because it extends well beyond the six main attack waves initially identified between September 15 and September 20. It also suggests that whatever set of wallet credentials the operator obtained remained usable days after D’CENT began warning App Wallet users to move their assets.

Wallet Count Rises to 7,393 as Activity Continues After D’CENT Warning

XRPL.to’s latest ledger reconstruction identifies 7,393 affected wallets. Of those, 4,756 were swept through outgoing payments, while another 2,637 accounts were deleted while still holding XRP.

The first major wave began on September 15, when 1,682 wallets lost approximately 3.62 million XRP in a matter of hours. The activity combined manual transfers from some of the largest wallets with automated scripts that attempted to drain balances down to the XRP Ledger’s required account reserve.

Five additional waves followed through September 20. But the activity did not end there.

Between September 21 and September 25 at 05:28 UTC, the reconstruction found another 1,112 wallets affected. That group included 345 wallets that had not previously been touched, while 76 wallets were emptied, subsequently funded again and then drained a second time.

That last group is particularly important. A wallet being funded again after an initial theft and then losing the new deposit indicates that control of the underlying signing credentials had not disappeared when the first balance was removed. The operator could apparently return whenever assets became available.

D’CENT said it received its first report of an unauthorized transfer on September 16. In its official status report, the company said potentially affected wallets included addresses whose recovery phrases had at some point been entered into the software-based App Wallet and that had a history of signing transactions using versions of the app earlier than 8.1.0.

The company advised affected users to update the application, create a wallet using an entirely new recovery phrase and transfer assets to the new address. It also told users not to restore or reuse the old recovery phrase.

More Than 6,000 XRP Accounts Were Deleted With Valid Keys

The account deletions provide some of the clearest evidence about the level of control available to the operator.

XRPL.to identified 6,095 AccountDelete transactions involving affected accounts. On the XRP Ledger, deleting an account requires valid authorization from that account. The process can be used after most of a wallet’s balance has already been removed to recover the XRP that otherwise must remain as an account reserve.

In other words, these were not simply transactions exploiting a weakness in the XRP Ledger itself. The blockchain processed transactions carrying valid signatures associated with the victims’ accounts.

That distinction resembles a wider problem seen across recent crypto security incidents: a blockchain can correctly validate a transaction while still being unable to determine whether the person controlling the signing credentials is the legitimate owner. A recent signer-control flaw highlighted the related risk that technically valid authorization does not necessarily mean a transaction is economically safe.

The D’CENT case goes further because the repeated transactions point toward access to a substantial collection of wallet keys rather than one isolated signing failure.

At the latest accounting, 6,273,261 XRP had moved through THORChain using swap instructions tied to four Ethereum addresses. Another 3.25 million XRP moved into unionchain.ai, while roughly 546,000 XRP went through NEAR Intents and around 536,000 XRP reached Binance deposit tags.

Approximately 1.4 million XRP remained in operator-controlled wallets as of the September 25 snapshot.

The Real Security Problem May Be the Compromised Key Set

The most important unanswered question is no longer whether the XRP transactions were authorized cryptographically. They were. The harder question is how the operator obtained access to so many valid credentials in the first place.

The ledger cannot answer that.

It can show which accounts signed transactions, when the funds moved and where they went. It cannot determine whether private keys or recovery phrases were exposed through software behavior, compromised infrastructure, malware, a third-party service, an implementation problem or another attack path.

That evidentiary gap is common in crypto incidents. In the recent Payy bridge exploit, for example, blockchain records showed the result of an apparently authorized state update long before investigators could establish which component of the authorization process had failed.

There is also an important contrast with the Bitget backend compromise. Bitget has said its private keys were not stolen and that an attacker instead manipulated infrastructure feeding its authorization process. In the D’CENT-linked XRP drain, the ability to repeatedly sign directly from thousands of victim accounts makes the compromised-key question much harder to avoid.

The refilled wallets strengthen that interpretation. If an address is drained once, receives more XRP and is drained again without the user authorizing the second transaction, then moving the original balance was never the full solution. The address itself remained unsafe because whoever controlled its credentials retained the ability to sign.

That is why D’CENT’s instruction to generate a completely new recovery phrase matters more than simply moving coins temporarily. Transferring funds to another device while keeping the same compromised seed would reproduce the same key material and preserve the underlying risk.

Cross-Chain Movement Makes Recovery Progressively More Difficult

The other challenge is what happens after stolen XRP leaves the original network.

More than 6.27 million XRP moving through THORChain means a substantial portion of the stolen assets could be converted into Ethereum-based liquidity without depending entirely on a centralized exchange at the initial conversion stage. Funds can then be divided among additional addresses or moved into other services, increasing the number of parties investigators must coordinate with.

D’CENT says it is working with law enforcement, exchanges, blockchain operators and outside security specialists to trace assets and seek freezes. That may still matter when funds eventually touch identifiable centralized services.

But XRP and ETH do not contain the same issuer-controlled blacklist mechanism available to centralized stablecoins. Recent USDC freeze activity shows how an issuer can directly immobilize tokens at a particular address. Recovery of native XRP or ETH generally depends much more heavily on identifying exchange endpoints, custodians or other intermediaries capable of stopping withdrawal or conversion.

For investors, the remaining 1.4 million XRP in known operator-controlled wallets is therefore only one part of the recovery picture. The larger issue is how much of the already-routed balance can still be connected to services willing and able to intervene.

The incident also leaves D’CENT with a broader credibility test. Stopping new losses matters, but so does establishing how the affected credentials became accessible and whether the identified exposure can be conclusively bounded.

Until that root cause is established, the most consequential evidence may be the simplest: the same wallet keys continued working for the attacker days after the first drain, and wallets that received new funds could be hit again. That makes the stolen XRP only the visible outcome. The unresolved asset is the key set itself.

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *