Skip to main content
AVOID.NET

DCENT App Wallet Exploit (September 2026)

avoid.net/dcent-app-wallet-exploit-september-202610/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4A1pSt…QiNp

Summary

On September 15-16, 2026, attackers exploited a signing vulnerability in the DCENT App Wallet — the software wallet mode of the mobile application developed by South Korean company IoTrust Co., Ltd. — to drain funds from thousands of addresses across multiple blockchains. On-chain analysis identified approximately 6,160 XRP Ledger addresses as potential victims, with roughly 9.3 million XRP tokens stolen on that chain alone; the full cross-chain loss figure remains unconfirmed by DCENT as the investigation is ongoing. Hardware wallet devices manufactured by DCENT were not confirmed to be affected.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about DCENT App Wallet Exploit (September 2026)?

Timeline(6 events)

5 November 2025

DCENT App Wallet version 8.1.0 released — later identified as the last vulnerable release prior to which the signing vulnerability was present.

DCENT Preliminary Incident Report

15 September 2026

First attack wave begins at 16:29 UTC on the XRP Ledger. Automated script drains 204 wallets over 14 minutes, collecting 19,787 XRP. After a ~33 minute pause, a second wave resumes. By 18:34 UTC, 1,552 XRP Ledger wallets have been drained for a total of 2,009,321 XRP (over $2.8 million at time of attack).

The Crypto Basic — XRPL.to on-chain analysis

16 September 2026

DCENT detects abnormal asset transfers involving the App Wallet and publishes an urgent security notice via its official X account (@DCENTWALLETS), urging all App Wallet users to transfer funds immediately.

DCENT Official X Account / CryptoTimes

17 September 2026

DCENT publishes its preliminary incident report, confirming the vulnerability is related to signing code in app versions prior to 8.1.0 and stating the investigation is ongoing. The Crypto Basic publishes detailed on-chain analysis of the XRP Ledger attack waves.

DCENT Preliminary Incident Report; The Crypto Basic

17 September 2026

XRPL intelligence account identifies approximately 6,160 XRPL addresses as potential victims, with roughly 9.3 million XRP tokens stolen on that chain. Approximately 7 million XRP had already been moved to unidentified services; approximately 2 million XRP remained in trackable addresses.

Coin Turk — XRPL intel account analysis

20 September 2026

DCENT issues updated guidance instructing users to update to App Wallet version 10.0.0 and use the built-in 'Check if action is needed' tool to assess individual exposure. KuCoin publishes a community notice relaying DCENT's security advisory.

KuCoin Community Notice; CryptoTicker
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 15 of 17 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 9/21/2026, 12:07:04 PM

last updated: 9/21/2026, 1:31:45 PM

1 view

avoid.net — verified advice for a post-truth world