7,393 wallets hit over 10 days, and thefts continued even after warnings went out. Here's the real cause, and the exact steps to protect yourself.
🔓 The worst part of this hack wasn't the first wave. It's that people kept losing funds a full week after the warnings went out.
A security breach targeting the D'CENT App Wallet drained roughly 12.4 million XRP from 7,393 wallets, spread across a ten-day window between September 15 and September 25.
⏱️ Here's how it actually unfolded.
The first wave was the worst by far, on September 15, attackers pulled around 3.6 million XRP from 1,682 wallets in under three hours, using a mix of manual and automated methods. That speed matters, it suggests the attackers already had access before the theft even started, rather than exploiting something in real time.
Users began noticing suspicious activity the very next day. On-chain analysts traced the pattern back to D'CENT's App Wallet, specifically versions older than 8.1.0, which had been released back in November 2025.
🔧 Here's what actually caused it.
This was a software-side vulnerability, not a hardware flaw. D'CENT's actual hardware wallet and biometric device were not compromised. The issue was tied to how private keys were handled in older versions of the companion app. If you never imported your recovery seed phrase into that app, your hardware wallet itself stayed safe.
⚠️ Here's the part that's genuinely hard to read.
Even after public warnings started circulating, more than 640,000 XRP was stolen after September 21, days into the public alert period. That means a real number of users either never saw the warning or didn't act on it in time. This is one of the clearest examples this year of why speed matters once a breach becomes public.
🔗 And yes, this connects to a story you've already seen.
Roughly half of the stolen XRP has already been laundered through THORChain, the same cross-chain protocol at the center of the Bitget hack debate. Two major thefts, same laundering route, same unresolved question about whether the protocol should be blocking known stolen funds.
✅ Your action checklist right now
1️⃣ Check your D'CENT app version. If you're running anything older than 8.1.0, update immediately, before doing anything else with the app.
2️⃣ Never enter your recovery seed phrase into any companion app unless you are certain it's necessary and the app is fully updated. Your hardware device is designed to keep that seed offline for exactly this reason.
3️⃣ If you used D'CENT's app wallet with an imported seed, move your funds to a fresh wallet with a newly generated seed phrase, don't just update and stay put, assume the old key may be compromised.
4️⃣ Turn on any available transaction alerts so you'd know immediately if unauthorized activity started on your accounts.
5️⃣ Follow official D'CENT channels directly for confirmed updates, rather than relying on secondhand information during an active incident like this.
✅ What this means for you
If you use D'CENT, treat this as urgent, not optional. The gap between the warning going out and people still losing funds is the actual lesson here, acting within hours matters more than most people realize during an active breach.
If you use a different hardware wallet, this is still worth your attention, the underlying lesson applies broadly, companion apps that handle private keys are often the weaker link compared to the hardware device itself.
If you're trying to build better security habits generally, this is a good real-world case for why keeping wallet software updated isn't a minor chore, it's a real, ongoing part of protecting your funds.
🟢 Best case going forward
D'CENT fully discloses the technical root cause, remaining affected users get clear guidance, and no further funds are lost as awareness catches up.
🔴 Risk scenario
More XRP continues draining from users who haven't updated or seen warnings, and the total loss climbs further before the vulnerability is fully contained.
👀 Three things to watch
1️⃣ D'CENT's official disclosure
Does the company release a full technical explanation of exactly how the keys were compromised?
2️⃣ Continued theft numbers
Does the drain finally stop, or does the total climb beyond 12.4 million XRP?
3️⃣ THORChain's response
Does the protocol address these funds the way it's being asked to in the Bitget case, or does the same debate repeat here?
💡 The key takeaway
A software flaw in an old app version turned into a ten-day, multi-million-dollar theft, and the most sobering detail isn't the hack itself, it's that warnings alone weren't enough to stop it in time for everyone.
If you use D'CENT's app wallet, checking your version right now takes two minutes. That's the entire point of this post.
That is the part worth watching.
This post is for informational and educational purposes only and is not financial advice. Crypto markets are volatile. Always conduct your own research before making financial decisions.
#BinanceSquare #XRP #CryptoSecurity #DCENT #Crypto