South Korean wallet provider D'CENT is investigating unauthorized transfers from its mobile App Wallet after on-chain analysts linked the incident to the theft of several million XRP from thousands of XRP Ledger addresses. The company first disclosed “abnormal asset transfers” on Sept. 16 and issued a preliminary incident report a day later.
D'CENT has not published a confirmed loss total, but external trackers have put the scale far higher than the company's public statements so far. Estimates range from about 2 million XRP moved in a two-hour window on Sept. 15 UTC to as much as 9.3 million XRP spread across more than 6,000 addresses, though those larger figures remain unconfirmed by the firm.
Who may be affected
According to D'CENT, users may be at risk if they entered a recovery phrase into the App Wallet, signed a transaction or approval with it, and did so on a version earlier than 8.1.0. The company said version 8.1.0 was released on Nov. 5, 2025.
The warning extends beyond XRP Ledger accounts. D'CENT said assets on Bitcoin, Ethereum, Tron and EVM-compatible networks including BNB Chain, Polygon, Base and Arbitrum are also within scope. It has not disclosed the exact technical flaw, saying those details could enable copycat attacks.
Hardware wallets not directly exposed
D'CENT said its hardware wallets are not affected unless the same recovery phrase used on the device was also restored into the App Wallet. The company also warned that simply updating the mobile app is not enough to secure an exposed wallet.
Instead, it is advising potentially affected users to generate an entirely new wallet with a new recovery phrase and move all assets into it, including coins, tokens, NFTs and staked positions. Reusing an existing recovery phrase, the company said, could recreate the same or a related key.
What the on-chain data shows
D'CENT has not released its own estimate of total losses. Independent XRP Ledger tracker XRPL.to reported that 2,009,321 XRP left 1,552 wallets in roughly two hours on Sept. 15 UTC, a sum worth around $2.8 million at the time according to the analysis cited by Korean media.
A later estimate from the XRPL Intel account on X raised the possible scale to about 9.3 million XRP across 6,160 addresses. At a CoinGecko price of $1.59 cited in the source report, that would amount to roughly $15 million. D'CENT has not confirmed either tally.
XRPL.to said transaction records alone do not reveal how wallet keys were obtained. Still, the pattern appeared unusual: the order in which wallets were drained seemed to match wallet creation dates more closely than account balances. Most of the affected XRP Ledger accounts were reportedly created between 2021 and 2023, and roughly a quarter had been funded from Korean exchanges such as Upbit, Bithumb and Coinone.
Investigation and next steps
IoTrust, the company behind D'CENT, told ZDNet Korea that it had received 110 reports by Sept. 18. It said it had asked South Korea's police cyber investigation unit and cryptocurrency exchanges to help freeze stolen funds.
Researchers cited by ZDNet Korea said weak randomness in how older app versions generated keys was the most likely explanation, but D'CENT has not confirmed that as the cause. The company said any recovery will depend on authorities, third parties and the outcome of its investigation, and it has not announced a compensation plan.
Source: www.blockhead.co