Self-Custody

D'CENT Wallet Hack: Find Every Copy of Your Seed Phrase

The D'CENT app wallet hack drained 2.01M XRP from 1,552 wallets. A seven-step audit to find every copy of your seed phrase, mining payout address included.

D'CENT app wallet hack: one 12-word seed phrase linked to a safe hardware chip and a drained app copy, 2.01M XRP taken in 2h 05m

On September 16, 2026, IoTrust, the South Korean company behind D'CENT wallets, posted an urgent notice: it had detected abnormal asset transfers involving the D'CENT App Wallet and told users to move their funds "as soon as possible to a secure hardware wallet or another trusted wallet address," as Bitcoin.com News reported. The D'CENT wallet hack had already happened by then. On-chain records analyzed by XRPL.to and published by The Crypto Basic show attackers draining 1,552 XRP Ledger wallets between 16:29 and 18:34 UTC on September 15, taking 2,009,321 XRP, worth more than $2.8 million at the time.

IoTrust says the problem appears limited to its software App Wallet, and it has not confirmed any impact from D'CENT hardware devices. The root cause is still under investigation. Its warning, though, covered two groups: anyone holding assets in the App Wallet, and anyone who used the same recovery phrase in both the App Wallet and a hardware wallet. That second group is why this story matters to you even if you have never heard of D'CENT. A hardware wallet keeps a key safe inside its chip. It cannot protect a copy of that key you typed somewhere else.

What the D'CENT Wallet Hack Data Shows

The numbers point to preparation. The attacker ran an automated script in two waves. The first drained 204 wallets for 19,787 XRP, then stalled because it ignored the extra reserve the XRP Ledger requires for trust lines. During a 33-minute pause, the operator manually emptied the 12 largest wallets, each holding more than 42,000 XRP, for 730,954 XRP. A fixed script then drained 1,336 more wallets for 1,258,563 XRP. Add the three waves and you get 1,552 wallets and roughly 2.01 million XRP, an average of about 1,295 XRP per wallet.

The order matters more than the totals. XRPL.to found the attack sequence correlated 0.65 with wallet creation dates and only 0.09 with balances. The attacker did not hunt for rich accounts in real time. They worked through a list of keys they already had. Most victim wallets dated from 2021 to 2023, and none was newer than March 2024. Whatever leaked those keys, it leaked them well before September 15.

Why a Mining Payout Address Belongs in This Story

If you mine solo, your reward lands in whatever address you typed into your miner's configuration. When you mine through NexusPool, the coinbase transaction pays that address directly, and NexusPool's Payout Preflight tool lets you confirm the payout goes where you intended before a block is ever found. Neither the pool nor the preflight check can tell you who else holds the keys behind that address. If the seed behind your payout address also lives in a phone app you tried once in 2022, a block reward could go to a wallet someone else can already spend from. Your odds of finding a block depend only on your hashrate relative to network difficulty, identical at every pool, and nothing in this post changes them. What you can change is whether the reward stays yours once it arrives.

Step by Step: Audit Where Your Seed Phrases Live

  1. List every recovery phrase you own. Write down each wallet by name, never the words themselves. Include old exchange-era apps, browser extensions, and any wallet you set up for a single airdrop.
  2. For each phrase, list every place you ever entered it. Hardware devices, phone apps, desktop wallets, password managers, a photo in cloud storage. The D'CENT warning turned on this question alone: IoTrust told hardware owners who never typed their phrase into the app that they needed to do nothing.
  3. Mark any phrase that appears in more than one place. Your security for that phrase matches the weakest place it lives. A hot app on a phone and a chip in a hardware wallet do not average out.
  4. Check your mining payout addresses against that list. Open your miner's configuration, copy each payout address, and confirm which wallet and which phrase control it. If you cannot tell, treat that as a finding.
  5. Retire any phrase you cannot fully account for. Generate a new wallet on a device you trust, verify the receiving address on the device screen, send a small test transaction first, then move the rest. Don't reuse the old phrase anywhere afterward.
  6. Update your miners before the next block, not after. Point each rig at the new address, then run a payout check again so the configuration matches the wallet you now control.
  7. Ignore anyone offering "recovery." IoTrust says it will never ask for recovery phrases, private keys, or transfers to a separate address for compensation, and it has no official support accounts on X. Every incident like this draws impersonators within hours.

What Stays Unknown

IoTrust has not said how the keys were exposed, and this post will not guess. The Crypto Basic's reporting notes that the laundering hub receiving the funds was created on August 9 and had already processed more than 1.36 million XRP from similar drains, which suggests September 15 was the operation's biggest day, not its first. Treat any confident explanation of the cause as ahead of the evidence until the company publishes its findings. This is not investment advice, and a clean audit of your own seeds does not make any wallet brand, D'CENT or otherwise, safe or unsafe. For more on how NexusPool keeps payouts out of pool custody, see the technology page and Glass Ledger, which records pool work and payouts in a form you can check offline.

To recap the sequence: list your phrases, list where each one lives, flag the duplicates, trace your payout addresses back to them, retire what you cannot account for, repoint your miners, and ignore anyone offering to help recover funds.

Trust nothing. Verify every place your seed phrase has ever been typed.