A compromise affecting D’CENT’s app-created wallets has drained more than $18 million in digital assets, including XRP, Bitcoin and Ethereum, raising fresh questions about recovery phrase security across multi-chain products.
A wallet incident that crossed networks
The breach began as an XRP theft but expanded across several blockchain networks. Protos reported that attackers drained more than 12.4 million XRP from over 7,000 wallets, with the stolen assets also including Bitcoin, Ethereum, Stellar and other cryptocurrencies.
The publication said the incident appears to involve recovery phrases generated through the D’CENT app, rather than a weakness confined to one blockchain or token. That distinction is important because a single recovery phrase can control assets on multiple networks. Once compromised, it can allow an attacker to move coins, tokens and other holdings from every supported chain tied to the same wallet.
D’CENT maker IoTrust has confirmed at least 110 abnormal transfer reports and identified Bitcoin, Tron and Ethereum among the affected assets, according to Protos. The attacks unfolded in several waves between September 15 and September 20. Attackers reportedly began by manually targeting wallets with larger balances before using scripts to sweep progressively smaller accounts.
Additional XRP was stolen after September 21, pushing the reported total above 12.4 million XRP. By September 26, Protos reported that 6.3 million stolen XRP had moved to Ethereum through THORChain. Researchers said much of the stolen value was no longer being held as XRP, complicating efforts to trace and recover the assets.
D’CENT’s response
In its official incident report, D’CENT describes the affected App Wallet versions, potentially exposed blockchain networks, the incident timeline and its coordination with law enforcement and exchanges. The company also outlines the migration steps users should follow.
The report places the focus on the App Wallet environment. That does not mean every D’CENT user is necessarily affected, but it does mean users need to determine how their recovery phrase was created and used. The risk is particularly significant for people who stored assets across several networks under one phrase.
D’CENT’s notice explaining who may be affected says users who operated an App Wallet before version 8.1.0 should check whether the security action applies to them. The notice also addresses cases in which users shared a recovery phrase between an App Wallet and a hardware wallet.
That configuration can expand the potential damage. If the phrase was generated or handled in the vulnerable app environment, moving assets on only one network may not be enough. Bitcoin, Ethereum, XRP, tokens and other holdings controlled by the same phrase could remain exposed.
What affected users should do
D’CENT is urging potentially affected users to create an entirely new recovery phrase and migrate their assets. The company’s migration guide instructs users to update the app, create a new wallet with a new recovery phrase and transfer coins, tokens and other assets to new addresses.
That migration should be treated as a full-wallet operation. Users need to account for assets on every supported network, along with NFTs and staked positions. Moving only a visible balance, such as XRP, could leave other holdings under the control of the old phrase.
Users should also avoid reusing the compromised recovery phrase when creating the replacement wallet. The new phrase should be generated in the updated environment, stored offline and never entered into websites, messages or unknown applications.
A broader infrastructure lesson
The incident illustrates both the convenience and the risk of multi-chain wallet design. Supporting several networks through one phrase simplifies portfolio management, but it also creates a larger blast radius when that phrase is exposed.
THORChain’s reported role in moving stolen XRP into Ethereum highlights another challenge. Cross-chain infrastructure can improve liquidity and give users access to assets across ecosystems, but it can also help attackers shift stolen funds quickly between networks. Once assets are converted, tracing and freezing them may become more difficult.
The breach is therefore not only a warning about one wallet product. It also underscores the importance of understanding how recovery phrases are generated, whether app and hardware environments share credentials, and what a provider’s migration process requires when a wallet is declared vulnerable.
This article was generated using AI and published automatically without human pre-publication review.
Read and checked by admin on 9/29/2026
How this article was made
The article was produced by the Grandmonts Media News Engine using automated research, drafting and verification workflows. No human editor reviewed the article before publication. Grandmonts Media remains responsible for the published content. Errors can be reported at office@grandmonts.cz.