T
iTokenly

D'CENT App Wallet (signing vulnerability) hack — September 2026

Verified — 3 sourcesLast checked September 19, 2026

Incident facts

Date of incident
Target typeWallet software or provider
Loss$2,860,000Price at time of incident
MethodPrivate key compromiseD'CENT says a signing vulnerability in its App Wallet exposed addresses that signed transactions on app versions before 8.1.0; it is withholding the technical detail on the grounds that it could be reused against others
ChainsXRP Ledger
OutcomeUnresolved

What happened

An automated drain emptied 1,552 XRP Ledger wallets belonging to users of D'CENT, a Korean wallet maker, between 16:29 and 18:34 UTC on 15 September 2026, taking 2,009,321 XRP, about $2.86m at that day's price.

It ran in two waves, according to an analysis by XRPL.to: 204 wallets in the first fifteen minutes, with 72 attempts failing, then a pause of 33 minutes while the operators manually emptied the twelve largest wallets, then 1,336 more wallets over 77 minutes. The attacker already held the keys and worked from a prepared list rather than scanning in real time; the wallets hit had mostly been created between 2021 and 2023.

D'CENT published a preliminary incident report on 17 September describing an App Wallet signing vulnerability, and is withholding the technical details on the grounds that they could be used in identical attacks. It says transactions signed on app versions earlier than 8.1.0, released in November 2025, may have exposed the address, and that the exposure covers Bitcoin, Ethereum, the XRP Ledger, Tron and EVM chains, along with tokens and NFTs sharing those keys. Hardware wallets are affected only where their recovery phrase was entered into the app. Users are told to update, create a new wallet with a new recovery phrase, move everything including staked assets and NFTs, and never reuse the old addresses for anything.

D'CENT says it is working with law enforcement, security specialists, mainnet teams and exchanges to trace the funds and seek freezes. It has made no commitment to compensate anyone. Only the XRP Ledger losses have been quantified, so the amount is a floor.

Sources

  1. D'CENT, preliminary incident reportPrimary · retrieved 2026-09-19
  2. The Crypto BasicSecondary · retrieved 2026-09-19
  3. Bitcoin.com NewsSecondary · retrieved 2026-09-19

Changes to this entry

  • Recorded four days after the incident. The amount is this registry's conversion of the 2,009,321 XRP identified by XRPL.to at the CoinGecko price for 15 September, about $1.42, which gives $2.86m; The Crypto Basic put it at over $2.8m. D'CENT says addresses on Bitcoin, Ethereum, Tron and EVM chains are exposed as well, but no losses there have been quantified, so the figure is a floor.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "D'CENT App Wallet (signing vulnerability) hack — September 2026", iTokenly, accessed 2026-09-19, https://itokenly.com/hacks/dcent-app-wallet-xrp
https://itokenly.com/hacks/dcent-app-wallet-xrp

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.