, , , ,

Millions in XRP Left Through a Phone App, Not a Broken Ledger

Close-up detail of a metal hardware-wallet plate and coiled USB cable on a desk blotter, blank folded paper, coffee ring stain, mechanical p

South Korea's D'CENT, operated by IoTrust, is investigating unauthorized transfers from its mobile App Wallet after on-chain trackers reported waves of XRP leaving thousands of addresses — a drain that did not require a hole in the XRP Ledger itself.

The company flagged "abnormal asset transfers" on September 16 and published a preliminary incident report the next day. D'CENT said users may be affected if they entered a recovery phrase into the App Wallet, signed a transaction or approval, and used an app version older than 8.1.0, released November 5, 2025. Bitcoin, Ethereum, the XRP Ledger, Tron, and EVM chains including BNB Chain, Polygon, Base, and Arbitrum are in scope. Hardware wallets are described as unaffected unless the same recovery phrase was restored into the app.

D'CENT has not published a loss total. XRPL.to tracked about 2.01 million XRP leaving 1,552 wallets in roughly two hours on September 15 UTC. Later tallies circulated by on-chain accounts put the potential pool near 6,000 to 6,700 addresses and about 9 million to 12 million XRP, with some estimates near $20 million across six waves through September 20; those broader figures are not confirmed by the company. IoTrust told ZDNet Korea it had 110 reports by September 18 and had asked police and exchanges to freeze funds. Researchers quoted in Korean coverage pointed to weak randomness in older key generation, which D'CENT has not confirmed.

The ledger cleared every stolen payment as valid. That is the point. Attackers used signatures from compromised keys, not a consensus bug. D'CENT is telling users that updating the app is not enough: they must generate a new phrase and move assets, because reusing a seed may recreate the same key. Who loses is anyone who treated a phone backup as a vault. The hardware device on the desk was never the hole. The phrase typed into an old app was.

Image source: i.ibb.co