Security Hub

Nearly $20M in XRP Drained From 6,678 Wallets in Wave Attack

Published: Sep 23, 2026By Aleksandar Dukic

Key Analysis

Almost $20 million in XRP was drained from 6,678 wallets across six attack waves between Sept. 15 and 20, 2026. Here is what is known and how to protect your keys.

Nearly $20M in XRP Drained From 6,678 Wallets in Wave Attack

Listen To This Article

Nearly $20M in XRP Drained From 6,678 Wallets in Wave Attack

5m 2s audio

AI narration. Useful for scanning on the move. Names and tickers may be mispronounced.

Nearly $20 million in XRP was drained from 6,678 wallets in a coordinated campaign that ran across six separate attack waves between September 15 and September 20, according to reporting from CryptoSlate. The scale of the theft, spread across thousands of individual holders rather than a single large target, points to a compromise at the wallet level rather than a protocol flaw on the XRP Ledger itself.

XRP was trading at about $1.50 as of September 23, 2026, down 5.5% over the prior 24 hours, the sharpest one-day drop among major assets that session.

The pattern behind six waves

On-chain analysts at XRPL.to traced the drains through September 20 and grouped them into six distinct waves rather than one continuous sweep. That staggered structure is the detail worth sitting with. A single exploit tends to empty everything it can reach at once. Repeated waves over five days suggest the attacker was working through a list of compromised credentials in batches, likely as more affected wallets were identified or as funds trickled back into drained accounts.

Nearly 6,678 wallets were hit for roughly $20 million combined, which averages out to a few thousand dollars per victim. That profile matches a mass-credential compromise: many small balances taken from ordinary users, not a whale or an exchange hot wallet. When thousands of unrelated wallets are drained in a short window, the common thread is almost never the blockchain. It is the software or the seed phrases people used to hold the keys.

D'CENT App Wallet in focus

Hardware wallet maker DCENT has told users of its App Wallet that exposed seed phrases must be replaced, per CryptoSlate's report. That guidance is the clearest signal so far of where the exposure sits. If seed phrases generated or stored in a specific wallet application were compromised, every asset controlled by those phrases is at risk, and simply moving funds to a new address derived from the same phrase does nothing. The phrase itself has to be abandoned.

For anyone who used the affected App Wallet, the practical response is blunt. Generate a fresh seed phrase on a device you trust, move any remaining funds to a wallet derived from that new phrase, and treat the old phrase as burned. Do not reuse it for any chain or any asset. A seed phrase that has been exposed once is exposed permanently, because the attacker can return to it at any point in the future, which is exactly the behavior these six waves demonstrate.

Custody exposure that spending products inherit

This incident is a reminder that the wallet layer, not the chain, is where most retail losses happen. It also has a direct read-across for anyone who spends crypto through a card. A growing number of self-custody options let users pay directly from a wallet they control, which removes exchange counterparty risk but shifts the entire security burden onto the user's own key management. If the seed phrase behind that wallet is compromised, the linked card balance is exposed the same way any other holding is.

The trade-off runs in both directions. Custodial crypto cards hold your funds on your behalf, which means a wallet-level seed phrase leak like this one does not touch them, but you inherit the custodian's counterparty risk instead. Self-custodial products flip that: no counterparty to fail, but no safety net if your own keys leak. Neither model is strictly safer. The relevant question is which failure mode you are better equipped to defend against, and events like this campaign show that seed-phrase hygiene is not a solved problem for the average holder.

Steps that actually reduce exposure

A few habits would have blunted this specific attack. Seed phrases should never be entered into, generated by, or backed up through software that touches the internet if it can be avoided; hardware signing keeps the phrase off connected devices entirely. Balances that are not being actively spent do not need to sit in a hot mobile wallet at all. And when a wallet vendor issues a replace-your-phrase notice, the window to act is short, because attackers work through exposed credentials in exactly the batched, repeated fashion XRPL.to documented here.

As of September 23, 2026, XRPL.to's tracing covers waves through September 20, and DCENT's public guidance is limited to replacing exposed App Wallet phrases. No attacker has been identified and no recovery of the drained XRP has been reported. This story may develop as more forensic detail emerges.

Overview

Nearly $20 million in XRP was drained from 6,678 wallets across six waves between September 15 and 20, 2026, in what appears to be a wallet-level credential compromise rather than an XRP Ledger flaw. XRPL.to traced the waves, and DCENT has told App Wallet users to replace exposed seed phrases. The takeaway is not specific to XRP: a leaked seed phrase is permanently compromised, and both self-custodial and custodial spending products inherit whatever custody model sits beneath them. If you used the affected wallet, move funds to a phrase you generated fresh on a trusted device and abandon the old one.

DisclaimerThis article is provided for informational purposes only and does not constitute financial advice. All fee, limit, and reward data is based on issuer-published documentation as of the date of verification.

Have a question or update?

Discuss this analysis with the community on X.

Discuss on X

Comments

Comments are moderated and may take a moment to appear.