DCENT, a prominent Korean wallet provider, has called on users of its App Wallet to take urgent security measures following reports of unauthorized transactions affecting multiple blockchain networks, including XRP Ledger (XRPL).
Investigation into Unusual Activity
The company reported detecting abnormal transfers involving its software-based App Wallet. An internal investigation identified the potential impact spanning several chains such as Bitcoin, Ethereum, TRON, XRPL, EVM-compatible networks, and others.
DCENT emphasized that all App Wallet users, including those who have imported or restored a hardware wallet recovery phrase through the software wallet, should immediately act to secure their assets. The provider urged users to first update to version 10.0.0 of the DCENT app and then use the built-in tool “Check if action is needed” to assess whether additional steps are required.
App Wallet users who entered their recovery phrases are considered especially at risk, regardless of whether they currently use a hardware wallet.
Recommendations Issued
DCENT instructed users to move their digital assets from any affected App Wallet to a different wallet created with a brand new recovery phrase, strictly advising against reusing old recovery phrases for new wallets. Transactions should not proceed through the software wallet until the update and necessary checks are completed.
The company stated that the most crucial step now is to “prevent further damage,” and migration to a more secure environment should be prioritized by all exposed users.
DCENT continues to issue scam alerts, clarifying it operates only through official support accounts on X and maintains no support channels on Telegram or Discord. Users are reminded that DCENT will never ask for private data such as recovery phrases, wallet keys, or PINs, nor instruct users via direct messages to transfer assets.
Scope of the Breach
After flagging the unauthorized transactions, DCENT published guidelines identifying users potentially impacted. The risk group includes any address where a recovery phrase was entered into the software wallet, addresses with a history of outgoing transactions—including token transfers, non-fungible token (NFT) activity, token approvals, or decentralized application interactions performed with app versions below 8.1.0 (released November 5, 2025) across major chains.
A recent assessment by the XRPL intel X account found that 6,160 addresses may be victims, with approximately 9.3 million XRP stolen.
Tracked funds indicate that 2 million XRP remain in monitored wallets, while 7 million XRP have been sent to unknown destinations, making recovery efforts challenging.
The incident also involved the theft of issued tokens collected in two specific wallets: one holding RLUSD and another maintaining various XRPL-issued tokens. As a precaution, token issuers have been urged to freeze the affected trust lines to block the movement of stolen assets, particularly those linked with RLUSD.
Tools for Traders in Volatile Markets
Given the reality that a single central bank announcement or an unexpected altcoin listing can shift market dynamics in moments, monitoring assets efficiently has become vital. Rather than managing charts, news, and portfolio trackers across multiple applications, investors are increasingly adopting privacy-focused platforms like CryptoAppsy that integrate real-time charts, price alerts, project news, and macroeconomic data all in one place. With no account required, these solutions aim to streamline asset management and reduce the risk of losses due to delayed reactions.




