
⏱ 2 min read
A single compromised recovery phrase turned a multi-chain wallet into a cross-chain breach, with at least 6.3M of the stolen XRP already swapped onto Ethereum via THORChain.
A breach of D’CENT’s multi-chain wallet has drained more than 12.4 million XRP from over 7,000 wallets and spilled beyond the XRP Ledger into other networks, Protos reported. D’CENT’s own disclosure named Bitcoin, Tron and Ethereum among affected assets, and a Stellar user also reported losses. IoTrust, D’CENT’s maker, told ZDNet Korea it had received at least 110 reports of abnormal transfers, including non-XRP assets.
Protos detailed at least six waves of theft between September 15 and 20 that emptied 6,678 wallets of 11.7 million XRP. The thief initially targeted larger wallets manually before automating drains from smaller balances. Community warnings did not halt the operation; an additional 640,370 XRP was taken after September 21, pushing the tally above 12.4 million.
The funds did not stay on the XRP Ledger. By Friday, 6.3 million of the stolen XRP had been swapped onto Ethereum via the cross-chain liquidity protocol THORChain, according to Protos. That figure implies roughly half of the known XRP haul (6.3 million versus just over 12.4 million) had already crossed to Ethereum. Researchers cited by Protos said, “Most of it is no longer XRP.”
How one breach became multi-chain
The link is the recovery phrase. D’CENT is a multi-blockchain wallet; once an attacker controls a user’s phrase, they can derive keys and sweep assets across all supported chains. Protos reported D’CENT now warns that wallets created using its app are vulnerable, urging users to generate a new recovery phrase and immediately migrate everything — tokens, NFTs and any staked assets. As recently as August, D’CENT promoted its hardware secure element’s resilience. A secure chip can protect keys at rest, but it does not neutralize a compromised recovery phrase or backup.
▼ 1.58%
▼ 0.66%
Liquidity routes complicate containment
As stolen funds are swapped through routers like THORChain and redeployed on destination chains, recovery options shrink. Protos separately reported that THORChain refused to block funds linked to the earlier Bitget XRP incident — a stance that underscores the limits of controlling flows on permissionless liquidity networks. The fast migration of assets off the source chain reduces the window for coordinated responses, especially when the losses span multiple networks.
What to watch next
Specifics still missing include a full post-mortem from IoTrust, a chain-by-chain breakdown of non-XRP losses and confirmation of addresses used for cross-chain swaps. Indicators to monitor: further transfers from known D’CENT-linked addresses into THORChain pools, consolidation on destination chains like Ethereum, and the pace at which D’CENT users regenerate seeds and move funds.
This content is for informational purposes only and does not constitute financial advice.
🧠 HafidWatch Take
When stolen assets move across chains faster than a critical threshold, traditional containment methods like blacklists lose efficacy because the window to act closes too quickly. This suggests that beyond blocking suspect addresses, defense strategies must integrate real-time monitoring and automated response tied to the asset flow speed. Improving seed management through per-chain key isolation offers a more resilient layer of security, as attackers increasingly exploit reused multi-chain credentials rather than protocol vulnerabilities.
🔗 Tools mentioned in this article
Affiliate disclosure: Links above may earn HafidWatch a commission at no cost to you.
Daily crypto intelligence. Before the market opens.
Including the Divergence Index — the sentiment gap no other newsletter tracks. Free, every morning at 7:30am ET.
✓ Free forever · ✓ No spam · ✓ 50+ sources monitored


