Writing · September 2026
A patch can't take back a key.
When a key to a house goes missing, nobody fixes it by oiling the lock. The lock works fine. That's the problem. It works just as well for whoever has the copy. You don't service the lock. You change the cylinder.
This week about 6,700 XRP Ledger wallets learned the difference.
What happened
On September 16, the wallet maker D'CENT posted a notice that it had "detected abnormal asset transfers involving the DCENT App Wallet," The Crypto Times reported. The App Wallet is the software wallet inside D'CENT's phone app, not its hardware devices. The company told users to move their assets.
Its incident report, dated September 17, narrows who is at risk: anyone whose recovery phrase was entered into the App Wallet, including hardware-wallet phrases restored there, and who signed transactions from an app version earlier than 8.1.0, released November 5, 2025. It lists Bitcoin, Ethereum, the XRP Ledger, TRON and EVM chains, on Android and iOS. It does not say what the flaw was. D'CENT says it is holding the technical details back so they can't be reused.
What the ledger shows
The XRP Ledger is public, so the drain can be read in order. The analytics site XRPL.to reconstructed it. The first wallet was emptied at 15:35 UTC on September 15. By the evening of September 20, one operator had emptied 6,678 wallets of 11,746,198 XRP, in six waves. Day one accounted for 3,618,110 XRP. September 16, the day of the first notice, was quiet. From the 17th on, five more waves took another 7,597,207 XRP.
That is one firm reading the ledger, and it has already revised its own day-one count once. Blockchain AI News checked part of it against a full-history node, and that part held up. I'd still call the totals a reconstruction, not an audit.
Most of the XRP left after the warning. I don't read that as people being careless. A notice on X doesn't reach everyone, and the exact scope came a day later. I read it as the attacker knowing something the users didn't: the keys still worked.
The detail that matters
This is the part I'd put in front of every wallet user. From September 17, XRPL.to says, the same keys were used again, this time to delete 5,001 accounts, most of them already empty, to collect the small reserve each one held. On the XRP Ledger, deleting an account takes that account's own key.
Think about what that means. The wallets were empty. The warning was out. The attacker came back and signed with those keys anyway, because none of that changed the keys.
An update fixes the software from here on. It can't reach back and un-leak a key that already got out.
D'CENT's own guidance says the same thing
Credit where it's due: the company doesn't pretend otherwise. Its report says to update the app, then "Create a wallet with a new recovery phrase," and "Do not restore a wallet using your existing recovery phrase." Its FAQ says to move everything, "including small balances," and to "Retire the old App Wallet and its recovery phrase permanently." It also says a hardware wallet is exposed if its words were ever typed into the App Wallet, because "both wallets are governed by the same private keys." Its self-check guide tells anyone unsure to assume they're affected.
That hardware-wallet line is the one I'd underline. The device on your desk is only as cold as the most connected place its words have ever been typed.
What I'd do
I lost 9 bitcoin to security mistakes. I don't treat rules like these as optional.
If a wallet maker tells you a recovery phrase may be exposed:
- Treat the phrase as dead, not wounded. Updating the app is step one. It is not the fix.
- Make a new recovery phrase on a device that never held the old one. Don't import the old phrase anywhere, hardware wallet included. Restoring it only gives the old key a new home.
- Move everything, dust and tokens too. D'CENT's report notes that tokens like USDT on Ethereum or TRON use the same wallet key as the coins.
- Don't wait for the root cause. D'CENT hasn't published one. The attacker didn't need one to keep going.
- Take instructions only from the vendor's own site and accounts. D'CENT warned against transfer instructions from unofficial channels. Every incident brings its own phishing.
And the standing rule, incident or not: a hardware wallet's recovery phrase never goes into a phone app. The moment it does, you have two wallets with one set of keys, and the security of the weaker one.
Change the cylinder. Don't oil the lock.
Verify everything, especially a key someone tells you is probably still fine.
— Jon Tetreault, September 2026. The habits, tools, and checks behind this piece are what I teach in Crypto Security Mastery.