Attackers stole roughly 11.7 million XRP, valued at nearly $20 million, from thousands of D’CENT App Wallet users in a multi-day operation that ran from September 15 to 20. On-chain analysis published by XRPL.to says the losses were spread across six separate waves and affected 6,678 wallets.
The findings indicate the incident was not caused by a flaw in the XRP Ledger itself. Instead, each transfer was signed with valid private keys from the affected wallets, pointing to a prior key compromise rather than a network-level exploit.
Six waves of theft over five days
According to XRPL.to’s forensic timeline, the attacker carried out the drain in six rounds between September 15 and September 20. The same script, manual tool, and set of stolen keys were reused throughout the operation, a pattern the researchers said points to a single coordinated actor behind the full sequence.
The theft was not limited to straightforward token transfers. XRPL.to reported that 5,001 accounts were deleted so the attacker could also collect their remaining reserve balances. Among those were 2,470 wallets that had never been swept for XRP, suggesting the attacker may have possessed a larger pool of compromised keys than the transfers alone initially showed.
Funds moved quickly across chains and services
The stolen XRP was routed out rapidly, narrowing the time available to freeze or intercept it. XRPL.to said about 5.6 million XRP was bridged to Ethereum through THORChain, while other funds were sent through exchanges including Binance and through services such as unionchain.ai and NEAR Intents.
As of September 21, around 1.3 million XRP was still sitting in wallets controlled by the attacker, according to the analysis. The rest had often reached off-ramps within hours of each sweep.
D’CENT says hardware wallets were not affected
D’CENT acknowledged abnormal transfers involving its App Wallet on September 16. The company said its hardware wallets were unaffected and later urged App Wallet users to move their funds immediately.
The company has not confirmed whether users will be reimbursed. The exact way the private keys were originally exposed also remains unconfirmed.
What is confirmed and what comes next
The clearest established point so far is that the XRP Ledger itself was not exploited. Every known sweep relied on valid signatures from the victims’ own private keys, which shifts attention to how those keys may have been compromised before the thefts began.
Security researchers cited in the reporting are recommending that anyone who has used D’CENT’s App Wallet migrate funds to a new wallet as a precaution. With the compromise method still unknown, that remains the most specific confirmed step tied to the incident.
Source: beincrypto.com