6,678 XRP Wallets Drained in Six Waves: Inside the $18.7M D'CENT Timeline
A six-day sweep pulled 11.75 million XRP out of 6,678 wallets, and nearly every transaction was validly signed. The chain did its job. The keys didn't. Here's the timeline, the exit route, and what it means for every hardware wallet holder.
Six waves. Six thousand six hundred seventy-eight wallets. Six days. And roughly $18.7 million of XRP gone before most holders even opened the app.
Here's the sequence. The timing is the story.
The Six Waves
The first sweep fired at 15:35 UTC on Sept. 15. Clean, signed, valid. Then 11.75 million XRP walked out of 6,678 distinct wallets between Sept. 15 and Sept. 20. At XRP's current $1.59, that's about $18.68 million. Call it twenty million with slippage.
D'CENT, the Korean wallet maker behind the App Wallet, got its first customer report on Sept. 16. One full day after the drain began. Notifications went out the same day through the app and official channels.
But the money kept moving. A second collection wave started at 07:05 UTC on Sept. 17. The final sweep in the traced dataset landed at 20:56 UTC on Sept. 20. Nearly six days of continuous extraction while users were being told to migrate.
Two methods ran side by side. Payment transactions cleared 4,208 wallets. Another 2,470 got emptied through account deletion with no preceding payment. The deletion piece is the clever part. An open XRP Ledger account carries a reserve, so a plain sweep leaves dust behind. An AccountDelete transaction closes an eligible account and forwards the remainder, minus the fee, to another address. One deletion moved 107,507 XRP on its own. At $1.59, that's about $171,000 in a single signature.
Investigators counted 5,001 AccountDelete transactions across 4,950 wallets, including accounts that had already been partially drained. And here's the detail that should make every hardware wallet owner sit up straight. The payment and deletion transactions were validly signed with the affected accounts' keys. The ledger record shows nothing about how those keys were obtained. D'CENT still hasn't disclosed the technical cause.
The chart is the chart. Signatures don't lie and they don't apologize.
The Exit Route
The stolen XRP didn't sit still. By 11:26 UTC on Sept. 21, 5.67 million XRP had moved through THORChain. Two collection waves pushed roughly 5.59 million XRP with memos specifying Ethereum destination addresses. That's a bridge crossing. Once XRP becomes something else on another chain, the trail gets a lot more expensive to follow.
Another 3.24 million XRP went to unionchain.ai. About 546,080 hit NEAR Intents. Some 535,666 landed in Binance deposit tags. Roughly 1.31 million XRP stayed in linked wallets at the snapshot.
So who loses? Holders, first and always. D'CENT says it's working with Korean law enforcement, outside security specialists, and exchanges to trace the money and request freezes where possible. It hasn't announced a single completed freeze. Recovery depends on third parties controlling the rails the funds traveled. That's a polite way of saying the odds are long.
And the second wave of losses hasn't peaked yet. Impersonators already smell blood. D'CENT has said, correctly, that it will never ask for a recovery phrase, private key, or PIN, and will never hand out an address for recovery or compensation transfers. Ask yourself what share of drained users get hit again by a fake support account in the next thirty days. Historically speaking, it's not a small number.
The Part Everyone Skips
Here's the uncomfortable rule. If you ever typed your hardware wallet's recovery phrase into that App Wallet, moving the phrase back onto a device doesn't save you. Same phrase, same private keys. Exposure follows the words, not the metal.
D'CENT's criteria also flags addresses whose phrase was used in the App Wallet and that signed transactions on any app version earlier than 8.1.0, which shipped Nov. 5, 2025. If you signed anything before that build, the company wants you to reconstruct your own timeline. That's a rough ask for anyone who doesn't keep version logs.
Users who never entered a phrase into the app and never used the software wallet to sign are clear under current criteria. Everyone else should assume the phrase is burned.
This is the trade-off nobody prints on the box. Self custody makes you the perimeter. There's no fraud department. There's no chargeback. A hardware wallet protects keys from remote attack only while the phrase never touches a networked device. The moment it does, the hardware is decoration.
My take, and it won't be popular with wallet vendors. Every app that accepts a hardware wallet seed phrase as an import feature is shipping an attack surface disguised as convenience. That design choice is the root cause here, whatever the technical trigger turns out to be.
What Comes Next
Watch the version 8.1.0 disclosure. Whatever D'CENT finds determines whether this was a software flaw, a supply chain problem, or a user-side phrase leak. Those three answers carry very different consequences for every wallet vendor, not just this one.
Watch the exchange addresses too. Binance deposit tags and the unionchain.ai flows are the last real choke points. A freeze there's worth more than any dashboard full of pretty arrows.
And watch XRP itself. It trades at $1.59 and the market has mostly shrugged at $18.7 million. That's the honest read. The weekly structure hasn't broken. The invalidation point sits at the base of the recent range. Lose that on the weekly and the whole advance becomes a retest candidate instead of a breakout. But price isn't the real damage here.
Six waves over six days means the drain ran while warnings were live and users were still moving funds. Somebody out there signed a fresh transaction with an already-compromised phrase because they didn't know yet. That's the number nobody will ever publish. And it's the one that matters.