Hackers Drain More Than 12.4 Million XRP From 7,000 D'CENT Wallets

Over 12.4 million XRP drained from 7,000+ D'CENT wallets across four chains, as XRPL's Batch and Permission Delegation upgrades near mainnet activation.

(06:47 PM UTC)
4 min read
AI SummaryAI
  • Six theft waves between September 15 and 20 emptied 6,678 wallets of 11.7 million XRP.
  • 6.3 million stolen XRP crossed to Ethereum through THORChain by Friday.
  • IoTrust confirmed 110 abnormal transfer reports covering non-XRP assets.
  • XRPL Batch amendment holds 85-94% validator support with October 9, 2026 activation.
j5wc1pnr

Hackers Drain 12.4M XRP From D'CENT Wallets

Attackers have drained more than 12.4 million XRP (XRP) from over 7,000 users of the D'CENT wallet — Ripple's cross-border settlement asset — in the second-largest XRP theft of the year, second only to the 102.9 million XRP lost in the Bitget exchange breach. The damage reaches well beyond the XRP Ledger. D'CENT is a multi-blockchain wallet: a single compromised recovery phrase, the master secret behind every private key stored in the app, gave thieves simultaneous access to Bitcoin, Ethereum, Tron and Stellar balances belonging to the same users. IoTrust, the South Korean maker of D'CENT, has confirmed at least 110 abnormal transfer reports covering non-XRP assets, according to ZDNet Korea. On-chain records show the theft unfolded in at least six waves between September 15 and 20, emptying 6,678 wallets of 11.7 million XRP. A further 640,370 XRP left the ledger after September 21, per on-chain drain tracking of the attacker transfers, lifting the total above 12.4 million. The thief began by sweeping the largest balances by hand, then scripted the drain to work down through progressively smaller wallets; warnings from D'CENT and XRP community members failed to stop the outflow. By Friday, 6.3 million of the stolen XRP had crossed onto Ethereum through THORChain, the cross-chain bridge and swap service, and researchers monitoring the flows concluded that most of the proceeds were no longer held as XRP. The laundering pattern echoes what ZachXBT documented in the Bitget hack laundering, when 277,724 XRP moved through swap networks, and the Bitget hacker later shifted 54 million XRP from breach wallets. D'CENT's official incident report, published on X on September 17, now urges affected users to generate a fresh recovery phrase and migrate every asset — tokens, NFTs and staked balances included. The advisory stings: as recently as August, the vendor was marketing its hardware wallets' secure element as impervious to the vulnerability class exposed in the Coldcard hack.

Batch and Permission Delegation Near Activation

Even as that cleanup continues, the ledger is closing in on two upgrades aimed directly at institutional users. Vet, community lead at the XRPL Foundation, has confirmed that Batch and Permission Delegation have entered the final stage of validator voting, with roughly 11 days left before full mainnet activation. Batch — shipped as BatchV1_1 and fixBatchV1_2 — carries between 85% and 94% validator support and is slated to activate on October 9, 2026. PermissionDelegationV1_1 holds 82% support, with activation planned for October 5, 2026. The atomic batch design bundles multiple transactions into one indivisible package: either every operation executes or the whole bundle is cancelled. For corporate payment runs, the effect is that a settlement spanning dozens of invoices either completes in full or leaves accounts untouched, removing the risk that a counterparty's default strands funds in a half-completed commercial reconciliation — the core problem XLS 56 targets. Permission Delegation, standardized as XLS 75, answers banking-grade security requirements by letting institutions hand account permissions to third-party providers or internal departments without ever exposing the master private key. Validators are separately collecting votes for fixCleanup3_4_0, a change in the xrpld v3.4.0 release meant to stabilize the automated market maker liquidity pools shipped with recent versions. The institutional push has a technical echo at the core: Nik Bougalis, a cryptography engineer who spent years on the ledger before leaving in 2022, has returned to core development with proposals to move the architecture to 64-bit components and strip out raw pointers. Network usage frames the timing — XRP Ledger payments recently topped 1.14 million daily on-chain payments, well above the 30-day average — though code activation alone will not create demand; how quickly fintechs integrate the tools will decide that.

Key Compromise Meets Delegated Authority

For COINOTAG, the two developments form a single arc: the ledger's security story and its institutional story are converging. The D'CENT post-mortem points to a wallet-layer key compromise, not a protocol flaw — every attacker transaction is traceable on the XRP Ledger, and the 12.4 million XRP total can be independently verified on explorers. Yet Permission Delegation, arriving days later, delivers precisely what the hack exposed as missing: delegated authority without a master secret ever changing hands. Until wallet vendors close the operational gap that let one seed phrase sweep four chains, retail XRP holders will keep revisiting cold-storage paper wallet guides — even as the ledger's institutional tooling matures. Security, not throughput, remains the binding constraint on demand.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.

Price-Impacting News

More News Articles