The drain of XRP from D'CENT's mobile App Wallet was larger, longer and more methodical than first reported: blockchain analysis firm XRPL.to has now traced 11.75 million XRP leaving 6,678 distinct wallets across six attack waves between September 15 and September 20, a tally worth roughly $18.7 million at XRP's current price of about $1.59.

The new figures, published by CryptoSlate on Wednesday, widen the scope of the incident beyond the 9.3 million XRP and 6,160 addresses documented in initial reports last week — and they show the attacker kept collecting for nearly a week after the wallet vendor's first public warnings.

Six Waves, Two Extraction Methods

XRPL.to dates the first identified sweep to 15:35 UTC on September 15. D'CENT has said it received its first customer report in South Korea on September 16 and began notifying users through its app and official channels that day.

The collection then resumed anyway. Another wave began at 07:05 UTC on September 17, according to XRPL.to's timeline, and the final sweep captured in the investigation occurred at 20:56 UTC on September 20 — four days after the vendor's notifications started.

The attacker used two complementary extraction methods across the 6,678 wallets: 4,208 were swept through ordinary payment transactions, while another 2,470 were emptied through account deletion without a preceding payment in the traced dataset. XRPL.to counted 5,001 AccountDelete transactions originating from 4,950 wallets, including accounts that had already been partially emptied.

The deletions matter because XRP Ledger accounts hold a base reserve while open. An AccountDelete transaction closes an eligible account and forwards its remaining XRP, minus the deletion fee, to another address — letting whoever controls the keys harvest balances that a plain payment sweep would leave stranded. One such deletion moved 107,507 XRP, about $171,000.

Every payment and deletion in the dataset was validly signed with the affected accounts' own keys, XRPL.to found. The blockchain trail does not reveal how those keys were obtained, and D'CENT — the South Korean wallet brand operated by IoTrust — has not disclosed the technical cause of the incident. The company is investigating the unauthorized transfers with Korean law enforcement, outside security specialists, blockchain projects and exchanges, and Blockhead reported the company has not announced a completed freeze or recovery.

Where the XRP Went

Much of the stolen XRP had already left the XRP Ledger by the time investigators mapped the flows. As of 11:26 UTC on September 21, XRPL.to traced 5.67 million XRP through THORChain, including about 5.59 million XRP sent from two collection waves in transactions whose memos specified Ethereum destination addresses.

Another 3.24 million XRP flowed to unionchain.ai, which XRPL.to described as an exchange, while roughly 546,080 XRP reached NEAR Intents and 535,666 XRP moved into Binance deposit tags. About 1.31 million XRP remained in wallets linked to the operation at the investigator's snapshot.

The routing complicates recovery. Cross-chain venues such as THORChain and NEAR Intents exchange the XRP for assets on other networks, forcing investigators to follow new trails on each destination chain. Transfers to exchange-linked addresses offer potential intervention points, though a deposit address alone does not establish whether the funds were sold, withdrawn or remain accessible.

D'CENT's Escalating Warnings

With sweeps continuing into a seventh day — The Crypto Basic documented one user losing more than $100,000 in XRP and XLM — D'CENT escalated its guidance on September 20, asking the wider community to help reach App Wallet users who may not have seen earlier notices.

"The most important step to prevent further damage is moving assets out of the D'CENT App Wallet," the company said, urging affected users to update the app from an official app store and migrate holdings to a wallet created with an entirely new recovery phrase.

The migration requirement extends to some hardware-wallet users. Anyone who previously entered or restored a hardware wallet's recovery phrase inside the App Wallet should follow the same procedure — returning the same phrase to a hardware device does not generate new private keys, so prior exposure follows the phrase to the new device. D'CENT's impact criteria also include addresses whose recovery phrase was used in the App Wallet and that signed transactions on app versions earlier than 8.1.0, released November 5, 2025. Hardware users who never entered their phrase into the App Wallet and never signed with the software wallet do not need to migrate under the current criteria.

The company also warned of a second wave of potential losses from impersonators: D'CENT says it will never ask for a recovery phrase, private key or PIN, and will never provide a wallet address for users to send assets to for "recovery" or "compensation."

The incident remains under investigation, with no attribution announced and no root cause publicly confirmed. The signature pattern — validly signed transactions from thousands of independently generated wallets, gathered in scheduled waves — is consistent with a compromise of key material or key-generation inputs at the wallet layer rather than a flaw in the XRP Ledger itself.

TrustGrade tracks wallet vendors and custody infrastructure as part of its security coverage. Verified trust data: trustgrade.ai.