mt logoMyToken
ETH Gas
EN

D'CENT App Wallet Flaw Linked to Theft of Millions of XRP

Favoritecollect
Shareshare
D'CENT App Wallet Flaw Linked to Theft of Millions of XRP

D'CENT, the South Korean wallet brand operated by IoTrust, is investigating a wave of unauthorised transfers out of its mobile App Wallet that on-chain trackers estimate has drained several million XRP from thousands of addresses. The company first flagged "abnormal asset transfers" on Sept. 16 and published a preliminary incident report the following day.

According to D'CENT, users are potentially affected if they entered a recovery phrase into the App Wallet, signed any transaction or approval with it, and did so using an app version earlier than 8.1.0, which was released on Nov. 5, 2025. Assets on Bitcoin, Ethereum, the XRP Ledger, Tron and EVM chains including BNB Chain, Polygon, Base and Arbitrum are all in scope. The company has withheld technical details of the vulnerability, saying that publishing them "could be used in identical or similar attacks."

D'CENT says its hardware wallets are unaffected unless a device's recovery phrase was also restored into the App Wallet. Updating the app is not enough on its own. The company is telling affected users to create a wallet with a new recovery phrase and move all coins, tokens, NFTs and staked positions to it, warning that "reusing an existing recovery phrase may regenerate the same or a related key."

D'CENT has not published a loss figure. Onchain analytics site XRPL.to tracked 2,009,321 XRP moving out of 1,552 wallets in roughly two hours on Sept. 15 UTC, worth about $2.8 million at the time, according to its analysis as reported by Korean outlets. XRPL.to noted that the transactions alone cannot show how the keys were obtained.

A later tally by the XRPL Intel account on X put the potential victim pool at 6,160 addresses and about 9.3 million XRP, which would be worth roughly $15 million at the current price of $1.59, per CoinGecko . Those figures have not been confirmed by D'CENT.

The pattern of the attack suggests the thief was working from a list of already-compromised wallets. XRPL.to found that the order in which wallets were drained tracked their creation dates far more closely than their balances, and most victim accounts were created between 2021 and 2023. Roughly a quarter had been funded from Korean exchanges including Upbit, Bithumb and Coinone.

IoTrust told ZDNet Korea it had received 110 reports by Sept. 18 and has asked Korea's police cyber investigation unit and exchanges to freeze stolen funds. Security researchers quoted by the outlet pointed to weak randomness in how older app versions generated keys as the most likely cause, though the company has not confirmed this.

D'CENT said recovery will depend on "actions by authorities and third parties and on the outcome of the investigation," and has not announced any compensation plan.

➢ Stay ahead of the curve. Join Blockhead on Telegram today for all the latest in crypto.
+ Follow Blockhead on Google News
Disclaimer: This article is copyrighted by the original author and does not represent MyToken’s views and positions. If you have any questions regarding content or copyright, please contact us.(www.mytokencap.com)contact
More exciting content is available on
X(https://x.com/MyTokencap)
or join the community to learn more:MyToken-English Telegram Group
https://t.me/mytokenGroup