
More than 6,600 wallets were emptied between September 15 and 20 following a compromise of private keys.
AI-generated summary
The XRP Ledger allows the deletion of accounts via the AccountDelete instruction, transferring the remaining balance to another address. Attackers exploited this feature to drain compromised accounts.
Six waves, 6,678 victims. Between September 15 and 20, 11.75 million XRP evaporated from thousands of wallets linked to the mobile application of D’CENT, a South Korean manufacturer of hardware wallets. At the current price, around $1.59, theft reaches $18.68 million.
Although alerted, the D’CENT teams were not able to act in time to avoid the siphoning.
Key Points
11.75 million XRP, or $18.68 million, was stolen from 6,678 accounts between September 15 and 20
Attackers used the XRP Ledger’s AccountDelete instruction to recover down to minimum account reserves
5.67 million tokens crossed THORChain to Ethereum, others landed on Binance, NEAR Intents and unionchain.ai
D’CENT requires migration to a new seed phrase, including for holders of exposed hardware wallets
XRP: AccountDelete function hijacked to scrape funds
D’CENT says it received its first customer report in South Korea on September 16, the day after the first samples, and immediately alerted its users, via the application and its official channels. The alerts were not enough to stop the bleeding.
XRPL.to then reconstructed the timeline of the theft, transaction by transaction. The first identified sample dates back to September 15 at 3:35 p.m. UTC. A new wave of siphoning started two days later, on September 17 at 7:05 UTC. The last recorded sample dates from September 20 at 8:56 p.m. UTC. In this interval, 6,678 wallets were emptied, entirely or partially: 4,208 by simple payment transactions, 2,470 by account closure.
It’s at the heart of the AccountDelete instruction that everything happened. XRPL.to identified 5,001 of these transactions, issued from 4,950 wallets, including accounts already partially siphoned off.
Any XRP Ledger account must set aside a minimum reserve to remain open, currently set at a few XRP. This sum remains inaccessible to a traditional payment. AccountDelete closes the eligible account and sends the residual balance to the destination address, deletion fees deducted. The attackers therefore scraped to the bottom of the pot. One of these deletions moved 107,507 XRP at once, approximately $171,000.
Decisive point: all these transactions were validly signed with the keys of the accounts concerned. The XRP Ledger performed exactly as expected and experienced no failures. The compromise occurs upstream, on the side of the private keys, and the blockchain says nothing about how they leaked.
For its part, D’CENT has still not communicated the technical cause of the leak.
Crypto: 5.6 million XRP passed through THORChain
Not surprisingly, when investigators began tracking the flows, most of the loot had already left the XRP Ledger. As of September 21, XRPL.to had identified 5.67 million XRP that had already passed through the THORChain, including approximately 5.59 million from two siphon waves, with transaction memos pointing to Ethereum destination addresses.
The rest dispersed. XRPL.to records 3.24 million XRP sent to unionchain.ai, 546,080 XRP arrived on NEAR Intents and 535,666 XRP were dispersed via Binance deposits. Around 1.31 million XRP was still lying dormant in wallets linked to the operation at the time of the analysis.
This manipulation of funds is not improvised. THORChain and NEAR Intents allow funds to jump from one blockchain to another without an intermediary. Thus, no one is able to freeze anything, which forces investigators to start their tracing from scratch on each new network.
The 535,666 XRP sent to Binance offer hope for users harmed by the hack. Indeed, a centralized platform can block a deposit upon notification, provided it is notified before the conversion. D’CENT says it is working with South Korean authorities, external security specialists, blockchain projects and exchanges to obtain freezes. No finalized freeze or recovery has been announced at this stage.
D’CENT urges its users to abandon their seed phrase
Faced with the ongoing withdrawals, D’CENT toughened its message on September 20 and asked the crypto community to relay the alert to users who had not seen anything happening.
“The most important step to avoid further damage is to move assets out of the D’CENT App Wallet. »
D’CENT, manufacturer of hardware wallets, on
The procedure is twofold. Update the application from an official store, then transfer all the assets to a wallet generated from an entirely new seed phrase. And the instructions go far beyond just users of the mobile application.
Anyone who has ever entered or restored the recovery phrase for their hardware wallet in the App Wallet must also migrate. The reason is due to a principle rarely reminded to beginners: reusing the same seed phrase on a new device does not generate new private keys. The keys derive mathematically from the sentence. If it has leaked once, it remains compromised regardless of the hardware that hosts it.
D’CENT considers that an account is exposed if three conditions are met: the seed phrase has ever been entered in the App Wallet, this account has already signed a transaction, and this signature was made with a version of the application prior to 8.1.0, released on November 5, 2025.
On the other hand, a hardware wallet whose phrase has never been entered into the application, and which has never signed via the software wallet, is not concerned according to the company's current criteria.
For the 6,678 accounts already emptied, D’CENT indicates that it is still building the procedure supposed to measure the extent of the losses and establish the status of the assets. No compensation has been promised to date, and the South Korean manufacturer has not set a timetable.
AI outlook — possibilities, not facts
Massive migration of users to new seed phrases.
Very likely · Within weeks

In Taverny, three hooded men kidnapped a family to extort cryptocurrencies based on tax data stolen from Waltio in January 2026. The targeted assets dated from 2024 and had declined significantly, limiting the loot to a few hundred euros. Six suspects were indicted, including three in pre-trial detention, and the alleged mastermind is believed to be a man imprisoned in Auxerre.

The British government announces an investment of 500 million pounds over three years and the recruitment of 500 agents to fight against money laundering, targeting in particular cryptocurrencies and fintechs.

Seven suspects have been arrested in the United Arab Emirates and Sweden over a money laundering ring involving 70 million Swedish crowns. The alleged leader, targeted by an Interpol red notice, was arrested in the Emirates.

Rony Hadjedj, Franco-Israeli at the head of the fraudulent Airsoft software, was arrested in Morocco. This system allowed hundreds of brokerage sites to embezzle 950 million euros by manipulating savers' losses, before being dismantled by German justice.

South Korean police have opened investigations against 26 users of the Polymarket betting platform for illegal gambling. Cumulative stakes reach 17.6 billion won, identified via blockchain analysis despite the site being blocked by authorities.

A DOJ document revealed in February 2025 shows that an address linked to the al-Qassam Brigades advised avoiding Binance for cryptocurrency donations, while citing Trust Wallet, OKX, Bybit, RedotPay and Kast. The DOJ seized $560,000.