The D'CENT Drain, Minute by Minute: 1,552 Wallets, Two Batches, One Bug
On 15 September 2026, between 16:29 and 18:34 UTC, 1,552 XRP Ledger wallets were emptied into two addresses that did not exist when it began. D'CENT has since warned of abnormal transfers involving its App Wallet, and we have read that app separately. This is what the ledger itself says: every transaction, in order, and what the timing gives away about the tools and the list behind it.
In one screen
- The sweeps came in two batches from one script, with a 33-minute pause between them. Batch 1 got the reserve arithmetic wrong and failed on every wallet holding a trust line; batch 2 has it right to the drop.
- During the pause, the twelve richest wallets, every one above 42,000 XRP, were moved by hand with a different tool into a second address. That address still holds all 730,954 XRP.
- The script walked its list in the order the wallets were created, not by size. The keys were in hand before the first sweep; nothing on the ledger looks like reconnaissance.
- Cash-out began at 18:25, while wallets were still being emptied: a hop, eleven 6,000 XRP throwaways deleted into a laundering hub, then Binance deposit tags and the Bridgers bridge. About 236,000 XRP has reached a service; 1,808,974 XRP sits in four wallets.
- The victims are ordinary wallets made between 2018 and 2024, most first funded from an exchange, Binance first and the Korean exchanges Coinone, UPbit and Bithumb together second. None of them had ever signed a transaction carrying a wallet-app tag, so the ledger does not name the app. D’CENT’s notice does.
- Our own detection flagged the first collector 31 seconds in and missed the second, because its very first sweep was 88,528 XRP. That gap, and three others this incident exposed, are closed; the details are at the end.
Minute by minute
Nothing here required an exploit of the XRP Ledger. Each wallet signed an ordinary payment of nearly its whole balance. The ledger shows what the keys did and when; it cannot show how they were obtained.
One script, one bug
| Batch 1 | Batch 2 | |
|---|---|---|
| Window | 16:29:50 to 16:44:00 | 17:17:40 to 18:34:42 |
| Amount sent | balance − 1 XRP | balance − (1 + 0.2 × objects) XRP − fee |
| Wallets emptied | 204 | 1,336 |
| XRP taken | 19,787 | 1,258,563 |
| Wallets holding a trust line or other object | 5 of 204 | 304 of 1,336 |
| Failed attempts | 72 | 54 |
| Exact to the drop | — | 1,338 of 1,551 |
The first attempt on the wallet rQpTpg…jcaK came at 16:30:21 and asked for 49,206.577956 XRP from a balance of 49,207.577946: balance minus one XRP, to the drop. The wallet owns one object, so its reserve is 1.2 XRP and the ledger refused. The script tried the same sum twice more, at 16:32:10 and 16:50:21, and failed both times. At 17:12:30 the wallet was emptied by hand instead. The 74 other wallets that failed in batch 1 were all collected by batch 2, whose first payment at 17:17:40 is from a wallet that had failed at 16:31:21.
The corrected formula tells you what the operator learned in those 33 minutes: the owner reserve, and the fee. Batch 2 leaves exactly the reserve behind on 1,338 of its 1,551 sweeps; the rest differ by the fee of a retried payment. Both batches pay 10 drops per transaction and set the same fields; it is one program, edited once.
The twelve went by hand
The tool that moved the twelve is not the script. Its payments carry a SourceTag, 1741383633; pay a 20-drop fee instead of 10; set their expiry ledger to the current ledger plus the account's own sequence number, which is a bug no library makes; and leave exactly twice the reserve behind, the way an app with a safety margin does. They arrive 10 to 30 seconds apart, at typing pace, with a four-minute break after the sixth. The same tool created the operator's own provisioning wallet rf3v2W…HEez on 22 August; 23 of the 26 wallets that one funded fed the laundering hub.
The batch-2 script later visited all twelve and took the second reserve the tool had left, 1 to 4 XRP each, between 17:36:51 and 18:31:50. It did not know they had been handled; it was still working from its list.
The list came first
Every wallet was dusted with 10 drops 20 to 40 seconds after it was emptied. That is not the operator: the 47 wallets doing it have dusted 6,208 addresses since at least 12 September, exchange deposit addresses included, after any sizeable payment they see. Nothing the operator controls touched a victim before its sweep.
Where the money went
The hub rLBpP3…Ctcb predates this incident. It was created on 9 August by a KuCoin withdrawal and had passed 1.36 million XRP by the 16th, all of it from freshly made wallets, 418 of its 502 inflows account deletions. It pays wallets it creates itself, which deposit at exchanges within minutes and then delete themselves into a second hub, rHQMDz…1D54. Two earlier hubs of the same shape ran from 28 July and 29 July. Whatever this operation is, 15 September was its biggest day, not its first.
Who was hit
What the ledger cannot say
D’CENT’s notice of 16 September reports abnormal transfers involving its App Wallet and says hardware wallets are not affected. The ledger neither confirms nor contradicts that: 135 sampled victims signed 891 transactions before the drain and none carried a wallet-app tag, so which app they used is not written on chain. What the ledger does show is a list of 1,552 keys used from one place in one afternoon, in the order the wallets were created, with the largest handled separately. How the keys reached that place is the question the app matters for, and we have read the app.
On our side, the first collector was blocklisted 31 seconds after its first inflow and confirmed at 17:26; the second, which took the twelve, was not caught, because its first sweep was so large that our rule read the address as an institution. Since 16 September a whole-balance sweep fan-in trips on ten wallets and 100,000 XRP as well as on twenty-five wallets, a wallet holding nothing but a drainer's own payment is no longer treated as a treasury, and a destination that the drainer's throwaways delete themselves into is listed as a hub. All seven addresses below are on our scam list, which wallets can check before signing.
Check it yourself
The by-hand collector was shared publicly by James Rule XRP (@allthemoney) on 16 September at 11:51 UTC, sent to him by a community member who had been drained into it. Everything else here was found by following that one address.
- Collector, script: rDT8UPJM1Xd1MVbDi1R2bZH17MHWuvwPui
- Collector, by hand: rDAeWP5LfAzwBMvJZruCSzaWVF9sz9oXzj
- Hop: rE6Mxn7rTUUu7y1HqFnRMb6NJwSBBAi9UL · spare: rwWnFecB6jFAdaKHbA6GUYCaem477zc32v · to Bridgers: r91LKBRnVr7HBXjLRdxQ1WfUQ6FUAXSxFR
- Hubs: rLBpP3xKScTobDiXv16CvBC1G6X5JdCtcb · rHQMDzcxz6YgC2STnzGcDSDNfC6bP61D54
- Provisioning wallet: rf3v2WVUrxgpT6KxuepJHYFeFnLECTHEez
- First sweep 05136ACDA2… · first failure 0628003C05… · first by-hand sweep FFC37873B5… · batch 2 opens 44F8B4D10C… · the hop 5385E40363… · first Binance deposit B86287DCA0… · Bridgers 75A3CC71CA…
Times are ledger close times. Amounts are what the ledger delivered. If you hold one of these wallets, the whole sweep is visible from its own page on any explorer.