DCENT App Wallet Security Breach Stole 9.3 Million XRP

Unauthorized transfers affected 6,160 user addresses after a security vulnerability was identified in the app.

Updated on Sept. 20, 2026 in Financial Crime

Bold flat-color editorial illustration showing a partially open industrial steel vault door, symbolizing a security breach in digital asset storage.
A security vulnerability in the DCENT App Wallet led to the theft of 9.3 million XRP, affecting thousands of user addresses internationally. AI Illustration. Upload story photo >

Live Poll

Do you trust software-based digital wallets to keep your personal cryptocurrency holdings secure?

DCENT has reported a major security incident involving its software-based App Wallet, resulting in the theft of approximately 9.3 million XRP. The breach compromised 6,160 potential victim addresses across various blockchain networks.

Why it matters

This incident highlights ongoing security risks for digital asset holders using software wallets, specifically those running older, vulnerable software versions. Protecting recovery phrases and promptly updating applications remain critical defenses against such unauthorized transfers.

DCENT confirmed 6,160 addresses were targeted in the theft of 9.3 million XRP, with 7 million XRP already traced to unidentified services. The firm has released app version 10.0.0 to mitigate the vulnerability identified in versions below 8.1.0.

The players

DCENT

DCENT is a developer of hardware and software security solutions for digital assets.

The details

The security flaw impacted multiple networks, including Bitcoin, Ethereum, the XRP Ledger, and TRON. Users operating vulnerable software are instructed to update to version 10.0.0 immediately and transfer their assets to a new wallet configured with a fresh recovery phrase.

Timeline

  1. November 5, 2025: A vulnerable app version below 8.1.0 was initially released.

  2. September 20, 2026: DCENT urged users to take action following the security breach.

Legal Context

This breach underscores the persistent challenge of securing decentralized software wallets against evolving exploitation techniques. It follows the pattern established by the 2024 Ledger Connect Kit supply chain attack where software vulnerabilities were exploited to drain user funds.

Users currently running DCENT app versions older than 8.1.0 must immediately update to version 10.0.0 to secure their funds. Those affected should prioritize moving their remaining assets to a completely new wallet generated with a different recovery phrase.

The takeaway

Maintaining digital asset security requires vigilance regarding software version updates and the integrity of wallet recovery phrases. If you believe your wallet was compromised, migrating assets to a new, clean environment is the most effective way to prevent further unauthorized access.

Further reading

For more information on current threats to digital assets, visit the Financial Crime section.

Source note: This article includes information reported by U.

Live Poll

Do you trust software-based digital wallets to keep your personal cryptocurrency holdings secure?