- XRPL.to traced 11.75 million XRP, worth roughly $18.7m at the price it used, out of 6,678 separate wallets between 15 and 20 September.
- The sweeps came in six waves, and the last one it logged landed four days after D’CENT started warning users.
- What gave the attacker access has not been established publicly, so owners still have no way of checking whether they were exposed.
A total of 6,678 wallets were emptied of XRP over six days in September, according to the analysis firm XRPL.to. The transfers came in six distinct waves, and the final one it identified landed four days after the wallet maker involved had begun telling customers something was wrong.
Roughly £14m at current exchange rates has gone from wallets belonging to people who were holding their own coins, which is the arrangement the whole industry has spent years recommending over leaving money on an exchange.
The part that affects anyone still holding XRP in a wallet today is that no cause has been published. Without one, there is nothing an owner can check, no version number to compare against, and no way to establish whether their own keys were produced the same way.
What XRPL.to actually traced
The confirmed part of this story is the movement, because the XRP Ledger is public and anyone can read it. XRPL.to dates the first identified sweep to 15:35 UTC on 15 September. A further collection wave began at 07:05 UTC on 17 September, and the last one captured in its investigation happened at 20:56 UTC on 20 September.
Within that window it counted 11.75 million XRP leaving 6,678 distinct wallets. Of those, 4,208 were swept using ordinary payment transactions. Another 2,470 were emptied through account deletion with no payment before it, and across the dataset the firm identified 5,001 AccountDelete transactions originating from 4,950 wallets, some of which had already been partially emptied.
That second method is worth explaining, because it does not exist on most other networks. The XRP Ledger requires every account to hold a small reserve balance it cannot spend, which stops people creating millions of junk accounts. Deleting the account closes it and sends whatever is left, reserve included, to a destination address of the sender’s choosing. It is a normal ledger feature being used exactly as designed, by somebody who should not have had the keys.
The key, not the device
Your XRP does not sit inside a wallet the way cash sits in a purse. It sits on the ledger, a public record anyone can read. What you actually own is a : a very long secret number that proves the coins are yours and authorises them to move. Whoever holds that key controls the coins, and there is no bank to ring and no way to reverse a confirmed transaction.
A wallet, whether it is a small offline device or an app on your phone, is really just a place to generate and store that key. The security of the whole arrangement rests on the key being genuinely random, so enormous and so unpredictable that working it out is not worth attempting.
When that generation goes wrong, the usual protections stop applying. An attacker who can derive a key does not need your device, your PIN or your , and no amount of careful handling on the owner’s side makes any difference. That mechanism would fit a sweep of thousands of unconnected wallets inside a few days. It has not been confirmed as what happened here, and it should not be reported as though it has.
Hardware wallet, or the phone app?

The story has been widely summarised as a drain of hardware wallets. The narrower and more accurate version is that D’CENT, the Korean firm involved, warned users about unauthorised transfers involving its mobile App Wallet, which is software on a phone rather than the physical device the company also sells. Keys created by an app are not necessarily produced the same way as keys created by a separate offline device.
Which of the two produced the affected keys has not been set out publicly, and the distinction matters enormously to anyone deciding whether their own holdings are in scope. D’CENT says it received its first customer report in Korea on 16 September and began notifying users through its app and official channels that day. We have not seen a detailed public statement from the company setting out a cause, and no independent analyst has confirmed one.
Readers who saw separate reporting this month about Coldcard devices generating keys that were not random enough will spot the resemblance. Nobody has publicly linked the two, and they involve different companies and different products. What they share is the position the owners are left in, unable to establish from the outside whether they are affected.
What a UK holder can and cannot check
The ledger is open, so anyone can look up their own address on a block explorer and see every transaction recorded against it, including an AccountDelete. That will tell you whether funds moved. It will not tell you how the key was obtained, and it will not identify who did it.
Losses can be reported to Action Fraud, the national reporting centre for fraud and cybercrime in England, Wales and Northern Ireland, on 0300 123 2040 or at actionfraud.police.uk. In Scotland, reports go to Police Scotland on 101. Keeping the transaction hashes and timestamps is useful, because they are the only fixed record of what happened. Our guide to self-custody covers how keys and recovery phrases work in more detail.
What to watch
Whether D’CENT publishes a cause and, more usefully, a list of affected app versions or device batches. Until that exists, every owner is guessing, and that gap is doing damage of its own regardless of how many wallets turn out to have been at risk.
After that, whether XRPL.to’s count moves past 20 September. Six waves over six days suggests something being worked through methodically rather than a single opportunistic grab, and the totals in these cases are usually revised upwards before they settle.