D’CENT wallet hack drains 12.4 million XRP across five blockchains

Related

Share

A wave of thefts tied to the D’CENT wallet hack has grown into one of the biggest crypto security failures of the year, and it isn’t just an XRP problem anymore. What started as a drain on XRP Ledger addresses has now bled into Bitcoin, Ethereum, Tron and even Stellar, exposing a flaw that let attackers empty wallets across entirely different blockchains using a single stolen credential.

Key takeaways

  • The D’CENT wallet hack ranks as the second-largest XRP theft of 2026, behind only the Bitget exchange hack, which lost 102.9 million XRP.
  • More than 12.4 million XRP was drained from over 7,000 D’CENT wallets, a loss Yahoo Finance reported was worth roughly $20 million.
  • The breach spread beyond XRP to Bitcoin, Ethereum, Tron and Stellar, with at least one user losing XLM.
  • Attackers moved 6.3 million of the stolen XRP onto Ethereum’s blockchain through the THORChain swap service.
  • D’CENT is urging every affected user to generate a new recovery phrase and migrate all assets immediately.

Scope and Scale of the D’CENT Wallet Hack

The numbers behind this breach place it firmly among 2026’s largest crypto thefts, second only to the Bitget exchange hack. That single point makes clear why the incident matters beyond a niche wallet provider’s user base: it’s a reminder that hardware and software wallets marketed as secure can still fail at scale.

Details of XRP Theft

Hackers pulled more than 12.4 million XRP out of over 7,000 D’CENT wallets, a figure that dwarfs most single-incident crypto thefts reported this year outside of exchange breaches. Yahoo Finance, citing the scale of the drain, put the dollar value of the stolen XRP at around $20 million when it first reported the story. Compared with Bitget’s 102.9 million XRP loss, D’CENT’s numbers are smaller in absolute terms, but the breach still stands as the year’s second-largest XRP theft.

Spread Beyond XRP to Other Blockchains

What separates this incident from a typical single-chain exploit is how far it traveled. D’CENT’s own disclosure named Bitcoin, Tron and Ethereum as affected networks, and at least one Stellar user reported losing XLM in the same wave of thefts. IoTrust, the company behind D’CENT, confirmed at least 110 abnormal transfer reports involving non-XRP assets, according to ZDNet Korea. That detail underscores why this matters for anyone holding assets in a multi-blockchain wallet: a single point of failure can put every chain supported by that wallet at risk simultaneously, not just the one making headlines.

Timeline and Methodology of the Theft

The theft didn’t happen in one strike. It unfolded in coordinated bursts over roughly a week, starting with the largest wallets and working down to smaller ones as the attacker automated the process.

Waves of Theft Between September 15 and 20

At least six separate waves of theft hit D’CENT wallets between September 15 and 20, draining 6,678 wallets of 11.7 million XRP in that window alone. According to reporting on the incident, the thief initially stole from large wallets manually, then wrote scripts to systematically sweep progressively smaller balances once the manual approach proved effective. Warnings from D’CENT and members of the XRP community during that period failed to stop the bleeding: thieves took another 640,370 XRP after September 21, pushing the total past 12.4 million.

One Compromised Recovery Phrase, Many Blockchains

The mechanism behind the multi-chain spread comes down to how D’CENT’s wallet architecture works. Because it’s built as a multi-blockchain wallet, a single compromised recovery phrase gives an attacker the keys to sweep funds across every network tied to that wallet, not just one. That design choice, meant to offer convenience to users managing several assets in one place, became the exact vulnerability that let the theft jump from XRP to Bitcoin, Ethereum and beyond. Notably, D’CENT had promoted its hardware wallets’ secure element as recently as August, calling it impervious to the kind of vulnerabilities tied to the Coldcard hack.

Post-Theft Asset Movement and Impact

Once the XRP left D’CENT wallets, it didn’t stay put. Researchers tracking the stolen funds noted that a large share had already been converted into other assets, complicating efforts to trace or freeze the money.

Asset Migration via THORChain

By the end of the week, 6.3 million of the stolen XRP had crossed onto Ethereum’s blockchain through the swap service THORChain. That movement means the bulk of the stolen value is no longer sitting as XRP at all. As researchers following the case put it, “Most of it is no longer XRP.” This cross-chain laundering pattern is a familiar one in crypto theft cases, and it makes recovery efforts considerably harder once funds are converted and spread across multiple networks.

Security Warnings and User Recommendations

D’CENT is now telling users plainly that wallets created through its app carry ongoing risk, and that waiting to act could mean losing whatever assets remain. The company is urging anyone who set up a wallet through its app to generate a brand-new recovery phrase and move everything, including tokens, NFTs and staked assets, to a fresh, secure wallet immediately. That guidance applies regardless of which blockchain the holdings sit on, given that the vulnerability isn’t limited to XRP.

For the broader crypto industry, the episode is a pointed case study in the trade-offs of multi-blockchain wallet design. A single seed phrase that unlocks access to dozens of networks is convenient until it becomes a single point of catastrophic failure, and this breach shows how quickly that failure can cascade once it’s exploited.

FAQ

How much XRP was stolen in the D’CENT wallet hack?

More than 12.4 million XRP was stolen from over 7,000 D’CENT wallets.

Did the hack affect cryptocurrencies other than XRP?

Yes, the hack spread to other blockchains including Bitcoin, Ethereum, Tron, and Stellar, resulting in the loss of assets like XLM.

How did the hackers manage to steal funds across multiple blockchains?

Hackers used a single compromised recovery phrase associated with the multi-blockchain D’CENT wallet to steal funds across blockchains.

What has D’CENT advised users to do following the hack?

D’CENT warns users to create new recovery phrases and immediately migrate all assets, including tokens, NFTs, and staked assets.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.