Hackers Drained Over 7,000 D'CENT Wallets
A coordinated exploit compromised recovery phrases, moving stolen assets across the XRP Ledger, Bitcoin, and Ethereum.
Updated on Sept. 28, 2026 in Cybersecurity

Live Poll
Do you trust that your digital wallet provider is doing enough to secure your assets?
Hackers have drained more than 12.4 million XRP from over 7,000 D'CENT wallets in a series of attacks occurring throughout late September. IoTrust has confirmed the breach, which also extended to Bitcoin, Ethereum, and Stellar holdings.
Why it matters
The multi-chain nature of the theft demonstrates the systemic risk posed when a single compromised recovery phrase allows attackers to sweep assets across disparate blockchain networks. This exploit highlights the persistent vulnerability of hardware wallet security models to centralized credential exposure.
The attackers utilized a single compromised recovery phrase to drain 6,678 wallets across six waves between September 15 and September 20. By September 25, 6.3 million of the stolen assets had been bridged to the Ethereum blockchain using the THORChain protocol.
The players
IoTrust
The South Korean manufacturer of D'CENT hardware wallets, which secure digital assets across multiple blockchain protocols.
THORChain
A decentralized cross-chain liquidity protocol used by the attackers to move stolen XRP onto the Ethereum blockchain.
The details
The theft originated from the exploitation of recovery phrases—the master mnemonic keys used to derive private keys—allowing attackers to access multiple accounts across several blockchains. Attackers initially targeted large wallets manually before deploying automated scripts to sweep funds from smaller wallets. IoTrust, the manufacturer of D'CENT hardware wallets, confirmed the breach through at least 110 abnormal transfer reports involving assets beyond the XRP Ledger.
Timeline
September 15-20, 2026: Six waves of theft emptied 6,678 individual D'CENT wallets.
September 21, 2026: An additional 640,370 XRP were reported stolen.
September 25, 2026: Approximately 6.3 million stolen XRP were moved to the Ethereum blockchain.
The Tech Race
This breach underscores the growing sophistication of exploits targeting cross-chain asset management. While smaller than the 102.9 million XRP lost in the Bitget hack, the event highlights the operational efficiency attackers now achieve by automating drains across multiple chains.
Users of D'CENT wallets should immediately verify the integrity of their holdings and confirm their recovery phrases have not been exposed to third-party services. The extent to which these assets can be recovered remains limited by the decentralized nature of the affected blockchain networks.
The takeaway
The security of multi-chain wallets depends entirely on the absolute secrecy of the recovery mnemonic, as shown by the automated nature of this exploit. Users should monitor for additional disclosures from IoTrust regarding the specific technical path that led to the credential leak.
Further reading
For broader trends in asset protection and authentication, see our latest coverage on Cybersecurity.
Source note: This article includes information reported by Protos.
Live Poll
Do you trust that your digital wallet provider is doing enough to secure your assets?







