South Korean hardware wallet manufacturer D'CENT has confirmed a large-scale theft affecting users of its mobile app wallet, with attackers siphoning 11.75 million XRP, worth roughly $18.68 million at current prices, from 6,678 wallets over a six-day period between September 15 and 20.
According to on-chain analysis, the attackers used compromised private keys to move funds off the XRP Ledger. Of the affected wallets, 4,208 were emptied through simple payment transactions, while 2,470 were closed entirely using the ledger's AccountDelete instruction, a mechanism that permanently removes an account after transferring its remaining balance. XRPL.to recorded 5,001 AccountDelete transactions originating from 4,950 wallets during the attack window. The largest single transfer tied to an account closure moved 107,507 XRP, worth around $171,000.
The first withdrawal was traced to September 15 at 15:35 UTC. A second wave began on September 17 at 7:05 UTC, and the final recorded withdrawal occurred on September 20 at 20:56 UTC. D'CENT says it received its first customer report of unauthorised withdrawals on September 16, from a user in South Korea.
Funds routed through multiple chains
Tracing of the stolen assets shows 5.67 million XRP was funnelled through THORChain to addresses on Ethereum, with approximately 5.59 million XRP of that total coming from the two main withdrawal waves. Separately, 3.24 million XRP was sent to a wallet linked to unionchain.ai, while 546,080 XRP arrived on NEAR Intents and 535,666 XRP was deposited to Binance. At the time of analysis, an estimated 1.31 million XRP remained in wallets connected to the operation.
D'CENT hardened its warning to users on September 20 and asked the wider crypto community to help circulate the alert. In a post on X, the company urged holders to act immediately: "The most important step to avoid further damage is to move assets out of the D'CENT App Wallet."
No cause disclosed, no compensation promised
The company has identified app versions prior to 8.1.0, released on November 5, 2025, as exposing accounts to risk when signing transactions. D'CENT says it is working with South Korean authorities and external security specialists to investigate, but it has not disclosed the technical cause of the key leak, nor has it announced compensation for affected users or set a timeline for resolution.
For European holders of D'CENT devices, the incident underscores the exposure created by app-based signing on hardware wallets when private key material is mishandled, and the speed with which stolen assets can be dispersed across bridges and exchanges once a leak is exploited.




