Insights

The D'CENT Drain, Minute by Minute: 1,552 Wallets, Two Batches, One Bug

On 15 September 2026, between 16:29 and 18:34 UTC, 1,552 XRP Ledger wallets were emptied into two addresses that did not exist when it began. D'CENT has since warned of abnormal transfers involving its App Wallet, and we have read that app separately. This is what the ledger itself says: every transaction, in order, and what the timing gives away about the tools and the list behind it.

In one screen

1,552
wallets emptied
2,009,321 XRP
taken
2 h 5 min
first sweep to last, 16:29:50 to 18:34:42
2
collector addresses, both created by the first payment into them
126
sweeps that failed before the script was fixed
1,808,974 XRP
still parked in the operator’s wallets (16 Sep, 14:00 UTC)
  • The sweeps came in two batches from one script, with a 33-minute pause between them. Batch 1 got the reserve arithmetic wrong and failed on every wallet holding a trust line; batch 2 has it right to the drop.
  • During the pause, the twelve richest wallets, every one above 42,000 XRP, were moved by hand with a different tool into a second address. That address still holds all 730,954 XRP.
  • The script walked its list in the order the wallets were created, not by size. The keys were in hand before the first sweep; nothing on the ledger looks like reconnaissance.
  • Cash-out began at 18:25, while wallets were still being emptied: a hop, eleven 6,000 XRP throwaways deleted into a laundering hub, then Binance deposit tags and the Bridgers bridge. About 236,000 XRP has reached a service; 1,808,974 XRP sits in four wallets.
  • The victims are ordinary wallets made between 2018 and 2024, most first funded from an exchange, Binance first and the Korean exchanges Coinone, UPbit and Bithumb together second. None of them had ever signed a transaction carrying a wallet-app tag, so the ledger does not name the app. D’CENT’s notice does.
  • Our own detection flagged the first collector 31 seconds in and missed the second, because its very first sweep was 88,528 XRP. That gap, and three others this incident exposed, are closed; the details are at the end.

Minute by minute

Wallets emptied per minute, 16:25 to 18:36 UTC
010203016:3017:0017:3018:0018:30batch 1204 wallets, 19,787 XRP33-minute pausethe formula is fixed12 by hand, 730,953 XRPbatch 21,336 wallets, 1,258,563 XRP, 17.6 a minuteticks below the axis: 126 failed attempts
The gap is not a rest. The twelve largest wallets were moved during it, with a different tool, into a different address.
15 to 16 September 2026, UTC
16:29:50
First sweep
9 XRP from a wallet holding 10. The payment creates the collector rDT8UP…wPui; it did not exist before.
16:30:21
First failure, and our first flag
A 49,207 XRP wallet with one trust line: the script asks for balance minus 1 XRP, the ledger refuses (tecUNFUNDED_PAYMENT). In the same ledger our fan-in rule blocklists the collector, five senders in.
16:44:00
Batch 1 stops
204 wallets, 19,787 XRP, 72 failed attempts. The script has been hitting every wallet that holds a trust line.
17:05:20
The twelve richest, by hand
From 88,528 down to 42,001 XRP, one every 10 to 30 seconds, with a different tool, into a second address rDAeWP…oXzj. 730,953 XRP by 17:13:51.
17:17:40
Batch 2 starts, formula fixed
The first wallet is one that failed at 16:31. The script now subtracts the owner reserve and the fee, exact to the drop.
17:26:12
Sweep fan-in confirms the collector
25 unrelated wallets emptied into it inside the window. From here every later sweep into it is recorded as a drain.
18:25:32
719,476 XRP moves on
To rE6Mxn…i9UL, created by the payment, while batch 2 is still running.
18:34:42
Batch 2 ends
1,336 wallets, 1,258,563 XRP, at 17.6 wallets a minute. It also took the second reserve the by-hand tool had left in the twelve.
18:54:30
Peeling begins
The hop pays 6,000 XRP to a fresh wallet; at 19:11:40 that wallet deletes itself into the hub. Eleven times over four hours.
20:18:10
First exchange deposit
12,000 XRP into a Binance deposit tag, from a wallet the hub had created 2 minutes earlier.
01:48:10
Bridgers
118,400 XRP from r91LKB…SxFR into the bridge service in ten payments, the last at 03:07:51. (16 September)
05:27 to 05:45
Clean-up
Eight used cash-out wallets delete themselves into a second hub in 18 minutes.
09:20
D’CENT’s notice
Fifteen hours after the first sweep: abnormal transfers involving the App Wallet; update before moving anything.
From the first sweep to the first exchange deposit: 3 hours 48 minutes. To the bridge: 9 hours 18 minutes.

Nothing here required an exploit of the XRP Ledger. Each wallet signed an ordinary payment of nearly its whole balance. The ledger shows what the keys did and when; it cannot show how they were obtained.

One script, one bug

Batch 1Batch 2
Window16:29:50 to 16:44:0017:17:40 to 18:34:42
Amount sentbalance − 1 XRPbalance − (1 + 0.2 × objects) XRP − fee
Wallets emptied2041,336
XRP taken19,7871,258,563
Wallets holding a trust line or other object5 of 204304 of 1,336
Failed attempts7254
Exact to the drop1,338 of 1,551
An XRP Ledger account must keep 1 XRP plus 0.2 XRP per object it owns. Batch 1 forgot the objects, so a wallet with one trust line could not send what it was asked to send. 59 of the 126 failures are that; 65 are the script asking an already-emptied wallet again.

The first attempt on the wallet rQpTpg…jcaK came at 16:30:21 and asked for 49,206.577956 XRP from a balance of 49,207.577946: balance minus one XRP, to the drop. The wallet owns one object, so its reserve is 1.2 XRP and the ledger refused. The script tried the same sum twice more, at 16:32:10 and 16:50:21, and failed both times. At 17:12:30 the wallet was emptied by hand instead. The 74 other wallets that failed in batch 1 were all collected by batch 2, whose first payment at 17:17:40 is from a wallet that had failed at 16:31:21.

The corrected formula tells you what the operator learned in those 33 minutes: the owner reserve, and the fee. Batch 2 leaves exactly the reserve behind on 1,338 of its 1,551 sweeps; the rest differ by the fee of a retried payment. Both batches pay 10 drops per transaction and set the same fields; it is one program, edited once.

The twelve went by hand

Every emptied wallet, ranked by what it held (both axes logarithmic)
1101001k10k100klargest10th100th1,000th1,552nd42,001 XRP: above this line, by hand88,528the script's largest: 41,749637 wallets held between 9 and 11 XRP
The split is clean: every wallet above 42,000 XRP went by hand, none below. Someone had the list sorted by balance.

The tool that moved the twelve is not the script. Its payments carry a SourceTag, 1741383633; pay a 20-drop fee instead of 10; set their expiry ledger to the current ledger plus the account's own sequence number, which is a bug no library makes; and leave exactly twice the reserve behind, the way an app with a safety margin does. They arrive 10 to 30 seconds apart, at typing pace, with a four-minute break after the sixth. The same tool created the operator's own provisioning wallet rf3v2W…HEez on 22 August; 23 of the 26 wallets that one funded fed the laundering hub.

The batch-2 script later visited all twelve and took the second reserve the tool had left, 1 to 4 XRP each, between 17:36:51 and 18:31:50. It did not know they had been handled; it was still working from its list.

The list came first

Batch 2: the order the script took the wallets in, against the year each wallet was created
20212022202320241st400th800th1,200thmedian creation year, per 167 wallets
Rank correlation between sweep order and creation date: 0.65. Between sweep order and balance: 0.09. The script walked a list ordered by when the wallets were made, not by what they held.

Every wallet was dusted with 10 drops 20 to 40 seconds after it was emptied. That is not the operator: the 47 wallets doing it have dusted 6,208 addresses since at least 12 September, exchange deposit addresses included, after any sizeable payment they see. Nothing the operator controls touched a victim before its sweep.

Where the money went

2,009,321 XRP: where it is on 16 September, 14:00 UTC
Swept by the script into the first collector · 1,540 wallets, two batches1,278,350 XRP
Moved by hand into the second collector · the 12 wallets above 42,000 XRP; nothing has left it730,954 XRP
One hop on, 18:25 · holds 653,476; 66,000 peeled into eleven throwaways that deleted into the hub719,476 XRP
Into Bridgers, a bridge service · ten payments, 01:48 to 03:07118,400 XRP
Into Binance, four deposit tags · from eleven wallets the hub created, each used once112,498 XRP
Two more throwaways and a spare · 6,000 and 10,000 deleted into the hub; 15,000 parked31,000 XRP
Kraken and an unnamed hot wallet · 2,000 and 3,4625,462 XRP
It reconciles: the first collector took 1,278,350, sent 868,876 on and holds 409,544; the second holds its 730,954 untouched; the hop holds 653,476. 1,808,974 XRP has not reached an exchange. About 236,000 has: Binance, Bridgers, Kraken. Bridgers and the exchanges are services, not parties to the theft.

The hub rLBpP3…Ctcb predates this incident. It was created on 9 August by a KuCoin withdrawal and had passed 1.36 million XRP by the 16th, all of it from freshly made wallets, 418 of its 502 inflows account deletions. It pays wallets it creates itself, which deposit at exchanges within minutes and then delete themselves into a second hub, rHQMDz…1D54. Two earlier hubs of the same shape ran from 28 July and 29 July. Whatever this operation is, 15 September was its biggest day, not its first.

Who was hit

Where the 1,552 wallets were first funded from
Binance243 (15.7%)
Coinone114 (7.3%)
UPbit86 (5.5%)
Uphold84 (5.4%)
Bitrue64 (4.1%)
ChangeNow57 (3.7%)
Union Chain39 (2.5%)
KuCoin38 (2.4%)
Crypto.com28 (1.8%)
Bybit25 (1.6%)
Bithumb25 (1.6%)
Coinbase25 (1.6%)
Other, mostly personal wallets724 (46.6%)
Retail wallets, funded from a dozen exchanges and from personal wallets. Three Korean exchanges, Coinone, UPbit and Bithumb, activated 225 of them. No two victims are linked on chain except through whatever they had in common off it.
When the wallets were created
2018 to 202039 (2.5%)
2021255 (16.4%)
2022535 (34.5%)
2023685 (44.1%)
202438 (2.4%)
The youngest victim wallet dates from March 2024. Nothing created in the last eighteen months was on the list.

What the ledger cannot say

D’CENT’s notice of 16 September reports abnormal transfers involving its App Wallet and says hardware wallets are not affected. The ledger neither confirms nor contradicts that: 135 sampled victims signed 891 transactions before the drain and none carried a wallet-app tag, so which app they used is not written on chain. What the ledger does show is a list of 1,552 keys used from one place in one afternoon, in the order the wallets were created, with the largest handled separately. How the keys reached that place is the question the app matters for, and we have read the app.

On our side, the first collector was blocklisted 31 seconds after its first inflow and confirmed at 17:26; the second, which took the twelve, was not caught, because its first sweep was so large that our rule read the address as an institution. Since 16 September a whole-balance sweep fan-in trips on ten wallets and 100,000 XRP as well as on twenty-five wallets, a wallet holding nothing but a drainer's own payment is no longer treated as a treasury, and a destination that the drainer's throwaways delete themselves into is listed as a hub. All seven addresses below are on our scam list, which wallets can check before signing.

Check it yourself

The by-hand collector was shared publicly by James Rule XRP (@allthemoney) on 16 September at 11:51 UTC, sent to him by a community member who had been drained into it. Everything else here was found by following that one address.

Times are ledger close times. Amounts are what the ledger delivered. If you hold one of these wallets, the whole sweep is visible from its own page on any explorer.