D'CENT App Wallet Key Compromise
Attackers used compromised recovery phrases to sweep roughly 11.7 million XRP — about $18 million — from over 6,600 D'CENT App Wallet accounts across five chains.
Vuln-watch · relayed from a public source; see Source & attribution below
Summary
Attackers used compromised recovery phrases to sweep roughly 11.7 million XRP — about $18 million — from over 6,600 D'CENT App Wallet accounts across five chains.
Incident
- Victim: D'CENT Wallet
- Date (UTC): 2026-09-15
- Estimated loss: $18.0M
- Chain(s): XRP Ledger, Bitcoin, Ethereum, Tron, Stellar
- Attack type: private key compromise
- Funds status: stolen
Recommended actions
- If you use D'CENT Wallet, move funds to a fresh wallet with a new seed phrase once the vendor confirms the root cause
- Update the wallet software only from official sources
- Beware of follow-on phishing: ignore unofficial "refund", "recovery", or "claim" links and DMs; use the project's verified channels only
Source & attribution
Full analysis on Blockchain Breaches, 0xCERT's incident archive: https://www.blockchainbreaches.com/en/breaches/dcent-wallet-2026. Primary sources: https://protos.com/the-years-second-largest-xrp-hack-is-spilling-over-to-bitcoin-and-ethereum/ ; https://www.cryptotimes.io/2026/09/21/crypto-hacks-drain-20m-this-week-rseth-safe-nostra-fall/ ; https://thecryptobasic.com/2026/09/17/heres-how-the-dcent-wallet-hacker-drained-2-million-xrp-in-two-hours/.
References
- https://www.blockchainbreaches.com/en/breaches/dcent-wallet-2026
- https://protos.com/the-years-second-largest-xrp-hack-is-spilling-over-to-bitcoin-and-ethereum/
- https://www.cryptotimes.io/2026/09/21/crypto-hacks-drain-20m-this-week-rseth-safe-nostra-fall/
- https://thecryptobasic.com/2026/09/17/heres-how-the-dcent-wallet-hacker-drained-2-million-xrp-in-two-hours/
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-09-15 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0170/signed.txt | gpg --verify