{"investigation":{"slug":"dcent-app-wallet-exploit-september-2026","entity_name":"DCENT App Wallet Exploit (September 2026)","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"On September 15-16, 2026, attackers exploited a signing vulnerability in the DCENT App Wallet — the software wallet mode of the mobile application developed by South Korean company IoTrust Co., Ltd. — to drain funds from thousands of addresses across multiple blockchains. On-chain analysis identified approximately 6,160 XRP Ledger addresses as potential victims, with roughly 9.3 million XRP tokens stolen on that chain alone; the full cross-chain loss figure remains unconfirmed by DCENT as the investigation is ongoing. Hardware wallet devices manufactured by DCENT were not confirmed to be affected.","sections":[{"content":"On September 15, 2026, unauthorized asset transfers began draining funds from addresses associated with the DCENT App Wallet, the software-based wallet mode within the DCENT mobile application developed by South Korean company IoTrust Co., Ltd. DCENT detected the abnormal transfers and issued a public security alert on September 16, 2026, via its official X account (@DCENTWALLETS). According to DCENT's preliminary incident report, the issue was described as a signing vulnerability in app versions prior to 8.1.0, which was released on November 5, 2025. The company stated that, based on initial findings, the issue appeared to be limited to the DCENT App Wallet and that no impact on DCENT hardware wallet devices had been confirmed at the time of the alert.","heading":"Incident Overview","sources":[{"url":"https://store.dcentwallet.com/blogs/post/app-wallet-incident-report","name":"Preliminary Incident Report: App Wallet Signing Vulnerability — DCENT Official Blog","type":"official","credibility":1},{"url":"https://www.cryptotimes.io/2026/09/16/dcent-warns-app-wallet-users-after-detecting-abnormal-asset-transfers/","name":"DCENT Warns App Wallet Users After Detecting Abnormal Asset Transfers — CryptoTimes","type":"news_article","credibility":2},{"url":"https://x.com/DCENTWALLETS/status/2100076991798206573","name":"DCENT Wallet on X: Official Security Notice — @DCENTWALLETS","type":"social_media","credibility":2}],"severity":"critical"},{"content":"Blockchain analytics reviewed by XRPL.to, as reported by The Crypto Basic, show the attack on the XRP Ledger unfolded in two automated waves on September 15, 2026. The first wave began at 16:29 UTC with a small test transfer of approximately 9 XRP from a wallet holding 10 XRP into a newly created address. Over the following 14 minutes, the automated script systematically drained 204 wallets, collecting 19,787 XRP. After a pause of approximately 33 minutes — during which the twelve largest target wallets were handled separately — a modified version of the script was launched for a second wave. Between 16:29 and 18:34 UTC, a total window of approximately two hours and five minutes, 1,552 wallets were drained for a combined 2,009,321 XRP, valued at over $2.8 million at the time of the attack. The script's automation had a noted limitation: it failed to fully empty at least one wallet holding approximately 49,207 XRP because its logic only accounted for the standard 1 XRP account reserve, not the additional 0.2 XRP required per held object. The attack required no user interaction after the initial wallet compromise.","heading":"Attack Methodology and Timeline","sources":[{"url":"https://thecryptobasic.com/2026/09/17/heres-how-the-dcent-wallet-hacker-drained-2-million-xrp-in-two-hours/","name":"Here's How the D'CENT Wallet Hacker Drained 2 Million XRP in Two Hours — The Crypto Basic","type":"news_article","credibility":2},{"url":"https://en.coin-turk.com/over-2-5-million-in-xrp-stolen-from-1500-dcent-mobile-wallets-users-warned/","name":"Over $2.5 million in XRP stolen from 1,500 Dcent mobile wallets, users warned — Coin Turk","type":"news_article","credibility":2}],"severity":"critical"},{"content":"The on-chain footprint of the exploit spanned multiple blockchain networks. DCENT's internal investigation identified potential impact across XRP Ledger (XRPL), Bitcoin, Ethereum, TRON, and EVM-compatible networks, among others. An assessment by the XRPL intel account identified approximately 6,160 XRPL addresses as potential victims, with roughly 9.3 million XRP tokens stolen on the XRP Ledger chain alone. At XRP prices prevailing in mid-September 2026 (approximately $1.40 per XRP), 9.3 million XRP represents a USD-equivalent loss on that chain alone of approximately $13 million; the coin-turk.com article headline described this as a '$9.3 million theft,' which may reflect an earlier or lower XRP price point used at time of publication. Of the tracked XRP funds, approximately 2 million XRP remained in monitored wallets as of reporting, while approximately 7 million XRP had been moved to unidentified services, making recovery efforts uncertain. Additional stolen tokens were reported collected in two specific wallets: one holding RLUSD and another holding various XRPL-issued tokens. Cross-chain losses on Bitcoin, Ethereum, and TRON have not been independently quantified in verified sources reviewed as of this writing.","heading":"Scope of Impact: Chains and Addresses Affected","sources":[{"url":"https://en.coin-turk.com/dcent-urges-xrp-users-to-update-wallets-after-9-3-million-theft-linked-to-6160-addresses/","name":"DCENT urges XRP users to update wallets after $9.3 million theft linked to 6,160 addresses — Coin Turk","type":"news_article","credibility":2},{"url":"https://u.today/xrp-security-alert-web3-app-wallet-users-urged-to-act-now","name":"XRP Security Alert: Web3 App Wallet Users Urged to Act Now — U.Today","type":"news_article","credibility":2},{"url":"https://u.today/xrp-community-on-alert-as-web3-crypto-wallet-reports-security-breach","name":"XRP Community on Alert as Web3 Crypto Wallet Reports Security Breach — U.Today","type":"news_article","credibility":2}],"severity":"critical"},{"content":"DCENT's preliminary incident report identified the root cause as a signing vulnerability present in App Wallet versions prior to 8.1.0 (released November 5, 2025). The specific technical mechanism has not been publicly disclosed by DCENT as of the investigation's initial reporting phase. The vulnerability allowed unauthorized transactions to be generated and broadcast without requiring any user interaction after the initial wallet compromise. Users at elevated risk were those who: (1) created a wallet directly within the DCENT App Wallet; (2) imported a hardware wallet's recovery phrase into the App Wallet at any point; or (3) shared a mnemonic phrase between the App Wallet and a hardware wallet device. Users who exclusively connected a hardware wallet device to the app for transaction signing without ever entering their seed phrase into the app were stated to require no immediate action. DCENT has not confirmed whether the vulnerability involved compromise of seed phrase storage, a flaw in the transaction-signing logic, or a server-side component.","heading":"Vulnerability Details","sources":[{"url":"https://store.dcentwallet.com/blogs/post/app-wallet-incident-report","name":"Preliminary Incident Report: App Wallet Signing Vulnerability — DCENT Official Blog","type":"official","credibility":1},{"url":"https://store.dcentwallet.com/blogs/post/faq-dcent-app","name":"Frequently Asked Questions - DCENT App Wallet Security Issue — DCENT Official Blog","type":"official","credibility":1},{"url":"https://cryptoticker.io/en/dcent-app-wallet-withdraw-funds/","name":"D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now — CryptoTicker","type":"news_article","credibility":2},{"url":"https://www.kucoin.com/news/community/BTC/6ab053a862cf370007438914","name":"KuCoin Security Notice: DCENT Unauthorized Transfers","type":"other","credibility":2}],"severity":"critical"},{"content":"IoTrust Co., Ltd., the South Korean company behind the DCENT brand, issued an urgent public alert on September 16, 2026, urging all App Wallet users to transfer their assets immediately to a secure hardware wallet or a separate trusted address. The company instructed users to first update the DCENT app to version 10.0.0 (the patched release) and then use a built-in tool labeled 'Check if action is needed' to assess individual exposure. DCENT advised that users who must move assets should create a new wallet with a fresh recovery phrase rather than restoring from their existing phrase. The company stated it was working with law enforcement authorities, security specialists, mainnet operators and developers, and cryptocurrency exchanges to identify and trace funds related to the unauthorized transfers and to seek asset freezes where possible. DCENT also warned users that phishing and impersonation attempts were likely to follow the announcement and that the company would never request private keys, recovery phrases, or PINs through any channel. The company committed to publishing further updates through its official X accounts (@DCENTWALLETS, @DCENTWALLETS_KR, @DCENTWALLETS_JP) as facts were established.","heading":"DCENT and IoTrust Company Response","sources":[{"url":"https://store.dcentwallet.com/blogs/post/app-wallet-incident-report","name":"Preliminary Incident Report: App Wallet Signing Vulnerability — DCENT Official Blog","type":"official","credibility":1},{"url":"https://news.bitcoin.com/security/crypto-wallet-maker-dcent-tells-users-to-get-their-coins-out/","name":"Crypto Wallet Maker DCENT Tells Users to Get Their Coins Out — Bitcoin.com News","type":"news_article","credibility":2},{"url":"https://cryptoadventure.com/dcent-urges-app-wallet-users-to-move-funds-as-core-lightning-issues-security-alert/","name":"DCENT Urges App Wallet Users to Move Funds — CryptoAdventure","type":"news_article","credibility":2},{"url":"https://crypto-economy.com/crypto-wallet-maker-dcent-tells-users-to-transfer-funds-immediately/","name":"Crypto Wallet Maker DCENT Tells Users to Transfer Funds Immediately — Crypto Economy","type":"news_article","credibility":2}],"severity":"high"},{"content":"DCENT's security alert drew an explicit distinction between its App Wallet (a software-only wallet that generates and stores keys on the mobile device) and its hardware wallet devices (the Biometric Wallet, D'CENT X, and D'CENT S models, which store keys in a secure element on a physical device). As of the date of the preliminary incident report, DCENT stated it had not confirmed any impact on hardware wallets. Users who only ever connected a hardware device to the app for transaction confirmation — and who never entered their seed phrase into the mobile app — were stated to require no immediate action. This distinction is significant for users assessing their exposure: the exploit targeted the mobile app's key-handling code, not the hardware devices' secure element. However, users who had imported a hardware wallet's recovery phrase into the App Wallet at any point were considered at risk, as that mnemonic would have been processed by the vulnerable code.","heading":"Hardware Wallet Distinction","sources":[{"url":"https://store.dcentwallet.com/blogs/post/app-wallet-incident-report","name":"Preliminary Incident Report: App Wallet Signing Vulnerability — DCENT Official Blog","type":"official","credibility":1},{"url":"https://cryptoticker.io/en/dcent-app-wallet-withdraw-funds/","name":"D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now — CryptoTicker","type":"news_article","credibility":2},{"url":"https://blockfence.io/dcent-probes-abnormal-app-wallet-transfers-urges-users-to-move-assets/","name":"DCENT Probes Abnormal App Wallet Transfers, Urges Users to Move Assets — Blockfence","type":"news_article","credibility":2}],"severity":"medium"},{"content":"As of the initial reporting period (September 16-20, 2026), on-chain tracking of the XRP Ledger showed that approximately 2 million of the stolen XRP tokens remained in addresses that could be monitored, while approximately 7 million XRP had been transferred to external services, making tracing and recovery significantly more difficult. DCENT stated it was coordinating with exchanges in an attempt to freeze assets, though it acknowledged that the success of such efforts depended on the actions of third parties and on the outcome of the broader investigation. No confirmed freezes or asset recoveries had been publicly announced as of the most recent verified reporting reviewed here. The cross-chain losses on Bitcoin, Ethereum, and TRON have not been publicly quantified in verified sources, and no comprehensive multi-chain loss figure has been formally confirmed by DCENT or an independent security firm as of this writing.","heading":"Funds Tracing and Recovery Outlook","sources":[{"url":"https://en.coin-turk.com/dcent-urges-xrp-users-to-update-wallets-after-9-3-million-theft-linked-to-6160-addresses/","name":"DCENT urges XRP users to update wallets after $9.3 million theft linked to 6,160 addresses — Coin Turk","type":"news_article","credibility":2},{"url":"https://thecryptobasic.com/2026/09/17/heres-how-the-dcent-wallet-hacker-drained-2-million-xrp-in-two-hours/","name":"Here's How the D'CENT Wallet Hacker Drained 2 Million XRP in Two Hours — The Crypto Basic","type":"news_article","credibility":2}],"severity":"high"},{"content":"As of the date of this page's compilation (September 21, 2026), the DCENT App Wallet exploit investigation remains active and ongoing. Several material facts have not yet been publicly confirmed by DCENT or independent security researchers: (1) the precise technical root cause of the signing vulnerability; (2) the complete loss figure across all affected chains (Bitcoin, Ethereum, TRON, and EVM networks beyond XRP Ledger); (3) the identity or attribution of the attacker(s); (4) whether any law enforcement action has been initiated. DCENT's preliminary incident report explicitly stated it would be updated as facts were established. No independent post-mortem from a recognized blockchain security firm (such as SlowMist, CertiK, or Trail of Bits) had been published in verified sources reviewed here. This page should be updated when DCENT publishes a final incident report or when independent forensic findings are released.","heading":"Investigation Status and Open Questions","sources":[{"url":"https://store.dcentwallet.com/blogs/post/app-wallet-incident-report","name":"Preliminary Incident Report: App Wallet Signing Vulnerability — DCENT Official Blog","type":"official","credibility":1},{"url":"https://store.dcentwallet.com/blogs/post/faq-dcent-app","name":"Frequently Asked Questions - DCENT App Wallet Security Issue — DCENT Official Blog","type":"official","credibility":1}],"severity":"high"}],"timeline":[{"date":"2025-11-05","event":"DCENT App Wallet version 8.1.0 released — later identified as the last vulnerable release prior to which the signing vulnerability was present.","source":"DCENT Preliminary Incident Report","source_url":"https://store.dcentwallet.com/blogs/post/app-wallet-incident-report"},{"date":"2026-09-15","event":"First attack wave begins at 16:29 UTC on the XRP Ledger. Automated script drains 204 wallets over 14 minutes, collecting 19,787 XRP. After a ~33 minute pause, a second wave resumes. By 18:34 UTC, 1,552 XRP Ledger wallets have been drained for a total of 2,009,321 XRP (over $2.8 million at time of attack).","source":"The Crypto Basic — XRPL.to on-chain analysis","source_url":"https://thecryptobasic.com/2026/09/17/heres-how-the-dcent-wallet-hacker-drained-2-million-xrp-in-two-hours/"},{"date":"2026-09-16","event":"DCENT detects abnormal asset transfers involving the App Wallet and publishes an urgent security notice via its official X account (@DCENTWALLETS), urging all App Wallet users to transfer funds immediately.","source":"DCENT Official X Account / CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/16/dcent-warns-app-wallet-users-after-detecting-abnormal-asset-transfers/"},{"date":"2026-09-17","event":"DCENT publishes its preliminary incident report, confirming the vulnerability is related to signing code in app versions prior to 8.1.0 and stating the investigation is ongoing. The Crypto Basic publishes detailed on-chain analysis of the XRP Ledger attack waves.","source":"DCENT Preliminary Incident Report; The Crypto Basic","source_url":"https://store.dcentwallet.com/blogs/post/app-wallet-incident-report"},{"date":"2026-09-17","event":"XRPL intelligence account identifies approximately 6,160 XRPL addresses as potential victims, with roughly 9.3 million XRP tokens stolen on that chain. Approximately 7 million XRP had already been moved to unidentified services; approximately 2 million XRP remained in trackable addresses.","source":"Coin Turk — XRPL intel account analysis","source_url":"https://en.coin-turk.com/dcent-urges-xrp-users-to-update-wallets-after-9-3-million-theft-linked-to-6160-addresses/"},{"date":"2026-09-20","event":"DCENT issues updated guidance instructing users to update to App Wallet version 10.0.0 and use the built-in 'Check if action is needed' tool to assess individual exposure. KuCoin publishes a community notice relaying DCENT's security advisory.","source":"KuCoin Community Notice; CryptoTicker","source_url":"https://www.kucoin.com/news/community/BTC/6ab053a862cf370007438914"}],"sources_used":[{"url":"https://store.dcentwallet.com/blogs/post/app-wallet-incident-report","name":"Preliminary Incident Report: App Wallet Signing Vulnerability — DCENT Official Blog","type":"official","archive_url":"https://web.archive.org/web/20260921123204/https://store.dcentwallet.com/blogs/post/app-wallet-incident-report","credibility":1,"archive_timestamp":"2026-09-21T12:32:04+00:00"},{"url":"https://store.dcentwallet.com/blogs/post/faq-dcent-app","name":"Frequently Asked Questions - DCENT App Wallet Security Issue — DCENT Official Blog","type":"official","archive_url":"https://web.archive.org/web/20260921123229/https://store.dcentwallet.com/blogs/post/faq-dcent-app","credibility":1,"archive_timestamp":"2026-09-21T12:32:29+00:00"},{"url":"https://thecryptobasic.com/2026/09/17/heres-how-the-dcent-wallet-hacker-drained-2-million-xrp-in-two-hours/","name":"Here's How the D'CENT Wallet Hacker Drained 2 Million XRP in Two Hours — The Crypto Basic","type":"news_article","archive_url":"https://web.archive.org/web/20260921131612/https://thecryptobasic.com/2026/09/17/heres-how-the-dcent-wallet-hacker-drained-2-million-xrp-in-two-hours/","credibility":2,"archive_timestamp":"2026-09-21T13:16:12+00:00"},{"url":"https://en.coin-turk.com/dcent-urges-xrp-users-to-update-wallets-after-9-3-million-theft-linked-to-6160-addresses/","name":"DCENT urges XRP users to update wallets after $9.3 million theft linked to 6,160 addresses — Coin Turk","type":"news_article","archive_url":"https://web.archive.org/web/20260921123021/https://en.coin-turk.com/bill-miller-iv-sees-bitcoin-market-cap-undervalued-cites-us-deficit-risk/?rbsnp=1","credibility":2,"archive_timestamp":"2026-09-21T12:30:21+00:00"},{"url":"https://en.coin-turk.com/over-2-5-million-in-xrp-stolen-from-1500-dcent-mobile-wallets-users-warned/","name":"Over $2.5 million in XRP stolen from 1,500 Dcent mobile wallets, users warned — Coin Turk","type":"news_article","archive_url":"https://web.archive.org/web/20260921123024/https://en.coin-turk.com/ethereum-recovers-to-2500-as-spot-etf-outflows-hit-405-million-in-3-days/?rbsnp=1","credibility":2,"archive_timestamp":"2026-09-21T12:30:24+00:00"},{"url":"https://www.cryptotimes.io/2026/09/16/dcent-warns-app-wallet-users-after-detecting-abnormal-asset-transfers/","name":"DCENT Warns App Wallet Users After Detecting Abnormal Asset Transfers — CryptoTimes","type":"news_article","archive_url":"https://web.archive.org/web/20260921123615/https://www.cryptotimes.io/2026/09/16/dcent-warns-app-wallet-users-after-detecting-abnormal-asset-transfers/","credibility":2,"archive_timestamp":"2026-09-21T12:36:15+00:00"},{"url":"https://news.bitcoin.com/security/crypto-wallet-maker-dcent-tells-users-to-get-their-coins-out/","name":"Crypto Wallet Maker DCENT Tells Users to Get Their Coins Out — Bitcoin.com News","type":"news_article","archive_url":"http://web.archive.org/web/20260917164353/https://news.bitcoin.com/security/crypto-wallet-maker-dcent-tells-users-to-get-their-coins-out/","credibility":2,"archive_timestamp":"2026-09-17T16:43:53+00:00"},{"url":"https://crypto-economy.com/crypto-wallet-maker-dcent-tells-users-to-transfer-funds-immediately/","name":"Crypto Wallet Maker DCENT Tells Users to Transfer Funds Immediately — Crypto Economy","type":"news_article","archive_url":"http://web.archive.org/web/20260917125300/https://crypto-economy.com/crypto-wallet-maker-dcent-tells-users-to-transfer-funds-immediately/","credibility":2,"archive_timestamp":"2026-09-17T12:53:00+00:00"},{"url":"https://cryptoticker.io/en/dcent-app-wallet-withdraw-funds/","name":"D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now — CryptoTicker","type":"news_article","archive_url":"https://web.archive.org/web/20260921122923/https://cryptoticker.io/en/dcent-app-wallet-withdraw-funds/","credibility":2,"archive_timestamp":"2026-09-21T12:29:23+00:00"},{"url":"https://u.today/xrp-security-alert-web3-app-wallet-users-urged-to-act-now","name":"XRP Security Alert: Web3 App Wallet Users Urged to Act Now — U.Today","type":"news_article","archive_url":"https://web.archive.org/web/20260921132038/https://u.today/near-protocol-approaches-major-190-million-tvl-milestone","credibility":2,"archive_timestamp":"2026-09-21T13:20:38+00:00"},{"url":"https://u.today/xrp-community-on-alert-as-web3-crypto-wallet-reports-security-breach","name":"XRP Community on Alert as Web3 Crypto Wallet Reports Security Breach — U.Today","type":"news_article","archive_url":"https://web.archive.org/web/20260921131851/https://u.today/polymarket-hit-by-major-fraud-scheme","credibility":2,"archive_timestamp":"2026-09-21T13:18:51+00:00"},{"url":"https://blockfence.io/dcent-probes-abnormal-app-wallet-transfers-urges-users-to-move-assets/","name":"DCENT Probes Abnormal App Wallet Transfers, Urges Users to Move Assets — Blockfence","type":"news_article","archive_url":"https://web.archive.org/web/20260921122910/https://blockfence.io/dcent-probes-abnormal-app-wallet-transfers-urges-users-to-move-assets/","credibility":2,"archive_timestamp":"2026-09-21T12:29:10+00:00"},{"url":"https://cryptoadventure.com/dcent-urges-app-wallet-users-to-move-funds-as-core-lightning-issues-security-alert/","name":"DCENT Urges App Wallet Users to Move Funds — CryptoAdventure","type":"news_article","archive_url":"http://web.archive.org/web/20260917125354/https://cryptoadventure.com/dcent-urges-app-wallet-users-to-move-funds-as-core-lightning-issues-security-alert/","credibility":2,"archive_timestamp":"2026-09-17T12:53:54+00:00"},{"url":"https://x.com/DCENTWALLETS/status/2100076991798206573","name":"DCENT Wallet on X: Official Security Notice — @DCENTWALLETS","type":"social_media","archive_url":null,"credibility":2,"archive_timestamp":null},{"url":"https://www.kucoin.com/news/community/BTC/6ab053a862cf370007438914","name":"KuCoin Community Security Notice: DCENT Unauthorized Transfers","type":"other","archive_url":"https://web.archive.org/web/20260921132345/https://www.kucoin.com/news/community/BTC/6ab053a862cf370007438914","credibility":2,"archive_timestamp":"2026-09-21T13:23:45+00:00"},{"url":"https://en.cryptonomist.ch/2026/09/16/dcent-wallet-security-issue/","name":"D'CENT Wallet Security Issue Triggers Urgent User Asset Advisories — Cryptonomist","type":"news_article","archive_url":"http://web.archive.org/web/20260921123020/https://en.cryptonomist.ch/2026/09/16/dcent-wallet-security-issue/","credibility":2,"archive_timestamp":"2026-09-21T12:30:20+00:00"},{"url":"https://www.bitbase.com/news/xrp-security-alert-web3-app-wallet-users-urged-to-act-now","name":"XRP Security Alert: Web3 App Wallet Users Urged to Act Now — Bitbase News","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-09-21T12:07:04.707627+00:00","updated_at":"2026-09-21T13:31:45.53452+00:00"}}