Here’s How the D’CENT Wallet Hacker Drained 2 Million XRP in Two Hours

0
5
Here’s How the D’CENT Wallet Hacker Drained 2 Million XRP in Two Hours



On the afternoon of Sept. 15, 2026, more than 1,500 crypto holders lost their XRP in a major attack that targeted the D’CENT app wallet.

Notably, between 16:29 and 18:34 UTC, a period of just two hours and five minutes, attackers drained 1,552 wallets and took a total of 2,009,321 XRP, worth over $2.8 million at the time. 

All the affected users had at some point used D’CENT, a Korean wallet app and hardware-device maker with a large user base across Asia, the United States, the United Kingdom, and Canada. 

Hours after the event, D’CENT warned users to move their funds immediately. The company said the incident appeared to affect only its software-based App Wallet and not its hardware devices.

How the Attackers Drained 2M XRP

Records reviewed by blockchain analytics resource XRPL.to show that the attack came in two waves and involved automated software. 

The first wave started at 16:29 UTC with a small transfer. Specifically, the attacker moved 9 XRP from a wallet holding 10 XRP into a newly created address. Over the next 14 minutes, the script went through its target list and drained 204 wallets, collecting 19,787 XRP.

However, the script ran into a problem. About 30 seconds into the attack, it tried to empty a wallet holding slightly more than 49,207 XRP but failed. 

This is because, besides the 1 XRP reserve required for each account on the XRP Ledger to maintain as a balance, they also need another 0.2 XRP for each additional object they hold, such as a trust line. 

The script only allowed for the basic 1 XRP reserve. As a result, it could not drain wallets that held trust lines. When the first wave stopped at 16:44, the script had recorded 72 failed attempts.

The attacker then changed tactics. Notably, the automated script paused for 33 minutes, while another tool manually drained the 12 largest wallets on the target list. Each held more than 42,000 XRP. 

The operator moved the funds one wallet at a time, with transfers coming roughly every 10 to 30 seconds, into a second newly created address. By 17:13, that address held 730,954 XRP, more than one-third of the total stolen amount. It has not moved any XRP since then.

At 17:17, the automated attack started again after the attacker fixed the reserve calculation. The updated script accounted for the extra reserve required for every object held by an account. 

This second and much larger wave continued until 18:34. It drained another 1,336 wallets and collected 1,258,563 XRP. The script moved through the wallets at about 17.6 accounts per minute and calculated the required amount correctly in most cases.

The List Was Already in Hand

The order of the targeted wallets shows how the attack was prepared. Interestingly, the attackers did not just look for wallets with the largest XRP balances. Instead, the script moved through the accounts almost in the same order in which they had originally been created.

XRPL.to analysts found a 0.65 correlation between the order of the attacks and wallet creation dates. The correlation between the attack order and wallet balances was only 0.09. 

This suggests that the attackers did not scan the XRP Ledger in real time to find wealthy accounts. They appear to have already had a list of compromised wallets and then worked through that list.

This also suggests that the attackers had access to the private keys before the first transaction took place. The XRP Ledger records show exactly when the funds moved and where they went, but they do not show how the attackers obtained the private keys for the 1,552 wallets.

Looking to Cash Out the XRP

The attackers also started moving the stolen XRP toward exchanges before they finished draining the wallets. At 18:25 UTC, while the second wave was still underway, more than 719,000 XRP moved to a new address. The operators then split the funds into smaller amounts.

This included 11 transfers of 6,000 XRP each to disposable wallets. These wallets then immediately deleted themselves into a laundering hub. The same process continued for about four hours. The first stolen funds reached Binance at 20:18 UTC.

In the early hours of Sept. 16, about 118,400 XRP moved through the Bridgers cross-chain bridge service in 10 separate transactions between 01:48 and 03:07 UTC. By around 05:30 UTC, several cash-out wallets had deleted themselves into a second laundering hub.

Notably, the laundering hub was also not new. It had been created on Aug. 9 through a KuCoin withdrawal and had already processed more than 1.36 million XRP through similar drains. This suggests that the Sept. 15 attack was the operation’s biggest day, not its first.

Who Got Hit, and What’s Still Unknown

The affected wallets largely belonged to users who had been in crypto for several years. Most of the wallets had been created between 2021 and 2023. The youngest wallet on the target list dated to March 2024, and investigators found no newer wallets among the victims.

The wallets also showed links to several exchanges. Binance had originally funded about 15.7% of the affected wallets. South Korean exchanges Coinone, UPbit, and Bithumb collectively activated close to one-quarter of the compromised accounts. This is consistent with D’CENT’s large user base in South Korea.

By Sept. 16, about 1.8 million of the 2 million stolen XRP remained in wallets controlled by the attackers. Only around 236,000 XRP had reached an exchange or bridge. At press time, it remains unclear how the attackers first obtained the private keys.





Source link

Leave a reply

Please enter your comment!
Please enter your name here