Risk Radar

/ critical

D’CENT App Wallet Incident: Independent Analysis Estimates 2.0M XRP Swept Across 1,552 Wallets

D’CENT manufacturer IoTrust confirms abnormal App Wallet transfers. Independent XRPL analysis estimates 1,552 wallets and 2,009,321 XRP swept; hardware-only wallets are not currently described as affected and the root cause remains unknown.

September 18, 2026Last updated 10:30 UTC5 min read

D’CENT wallet manufacturer IoTrust has acknowledged abnormal asset transfers involving its D’CENT App Wallet and opened an urgent security investigation.

Independent XRP Ledger analysis indicates a large coordinated drain, but the manufacturer has not published a final loss figure or root cause.

CEXVia separates the incident into two evidence layers: manufacturer-confirmed scope/user guidance and developing on-chain loss reconstruction.

What IoTrust has confirmed

D’CENT says its initial findings indicate the issue is limited to the software App Wallet.

The manufacturer says it has not confirmed impact originating from D’CENT Hardware Wallets themselves.

However, a hardware-wallet user can still share risk if they previously typed, imported or reused the same recovery phrase in the App Wallet, because the seed is no longer protected exclusively by the hardware environment.

Latest official scope: pre-v8.1.0 App Wallet use

D’CENT’s September 17 clarification narrows the action group further.

The company says the issue is related to the App Wallet in versions earlier than v8.1.0, which was released on November 5, 2025 at about 07:40 UTC.

D’CENT says action is required if a user:

  • first installed the app before November 5, 2025; and
  • made transactions (signed) with the App Wallet in a version earlier than v8.1.0.

D’CENT says action is not required if a user:

  • first installed the app on or after November 5, 2025 (v8.1.0 or later); or
  • used the app before that date only with a hardware wallet and never signed with the App Wallet.

Users who imported or reused a hardware-wallet recovery phrase inside the App Wallet remain a distinct risk category because the seed was exposed to the software-wallet environment.

This is the latest manufacturer scope and supersedes broader early assumptions that every App Wallet installation was necessarily affected.

Independent XRPL reconstruction

XRPL.to published an independent reconstruction estimating that on September 15:

  • 1,552 XRPL wallets were swept;
  • 2,009,321 XRP moved through the attack sequence;
  • activity occurred in two primary automated waves;
  • there was an approximately 33-minute pause;
  • roughly 126 early sweep attempts failed before the script was corrected;
  • larger wallets were handled more manually;
  • a large portion of funds remained parked in a small number of wallets at the cited September 16 snapshot;
  • a smaller portion had moved toward exchange and bridge services.

These are on-chain reconstruction figures, not D’CENT’s final accounting.

Fund movements

Independent analysis reported portions of the XRP moving through infrastructure including Binance deposit tags and the Bridgers cross-chain bridge.

Those attributions indicate potential cash-out or cross-chain attempts. They do not establish that receiving services participated in the original compromise.

Estimated dollar loss

SlowMist’s public hacked-event database lists an estimated loss of approximately $6.57 million and identifies the attack method as Unknown.

That dollar amount must remain labelled an external security estimate because XRP’s market value changes and the manufacturer has not published final reconciliation.

What the blockchain cannot prove

The XRP Ledger can show affected accounts, timing, sequencing, destinations and service interactions.

It cannot prove by itself how private keys or recovery phrases were obtained, whether App Wallet software leaked seeds, whether a dependency was compromised, whether device malware contributed, whether phishing was involved or whether every swept wallet was a D’CENT user.

Possible root-cause classes

Until D’CENT publishes a post-mortem, credible possibilities include recovery-phrase exposure, software-wallet storage weakness, malicious/compromised dependency, application-update compromise, device malware, API/backend exposure, phishing or credential theft.

None is confirmed today.

Required user response

D’CENT’s guidance tells affected App Wallet users to move assets to a wallet using a new recovery phrase after updating the application.

Moving to a new address derived from the same potentially compromised phrase does not remove seed-compromise risk.

Users should ignore anyone requesting recovery words, private keys, PINs, remote-control access or “recovery fees.”

Hardware-wallet boundary

The incident shows why “I own a hardware wallet” is not enough to prove hardware-only security.

A hardware wallet’s key isolation remains intact only if the recovery phrase is never entered into a less-trusted software environment.

Evidence Status

Confirmed / Manufacturer

Abnormal transfers involving D’CENT App Wallet are under investigation; initial scope points to the software App Wallet; no confirmed impact originating from hardware wallets themselves; phrase reuse/import can create shared exposure; migration/security guidance has been issued.

Developing / Independent On-chain

1,552 XRPL wallets swept; 2,009,321 XRP moved; two-wave automation pattern; exchange/bridge cash-out attempts.

External Security Estimate

SlowMist estimates approximately $6.57M loss; attack method remains Unknown.

Risk Assessment

Critical self-custody / wallet-security risk.

The combination of a manufacturer-confirmed software-wallet incident and a large independent on-chain sweep warrants Critical status even though the root cause and final official loss are unknown.

What to Watch Next

D’CENT root-cause report, app-version analysis, affected-chain expansion, final loss/account count, seed-compromise mechanism, CEX freezes, fund recovery and any hardware-wallet scope change.

FAQ

Has D’CENT confirmed a 2,009,321 XRP loss?

No. That is an independent on-chain reconstruction.

Are D’CENT hardware wallets hacked?

D’CENT says it has not confirmed impact originating from hardware wallets themselves.

Can hardware-wallet users still be exposed?

Yes, if the same recovery phrase was entered or reused in the App Wallet or another compromised environment.

How many XRP wallets were swept?

Independent XRPL analysis estimates 1,552.

What is the confirmed root cause?

It is not yet confirmed.

What should affected users do?

Follow D’CENT’s official guidance and move assets to a wallet secured by a completely new recovery phrase while avoiding phishing or anyone asking for seed words/private keys.