A total of 1,552 users of cryptocurrency wallet service Descent’s app wallet suffered a large-scale hack, with 2,009,321 XRP stolen. The attacker is believed to have withdrawn XRP from multiple wallets in an automated way over about 2 hours, then moved part of the stolen funds to exchanges and cross-chain bridges.
According to blockchain outlet Decrypt on Sept. 17 (local time), the attack lasted about 2 hours 5 minutes from Sept. 15 at 4:29 p.m. to 6:34 p.m. The stolen XRP was worth more than $2.8 million at the time.
The damage was concentrated in Descent’s software-based app wallet. Descent recommended that users move assets immediately to another wallet a few hours after the incident. The company said it found abnormal asset transfers in the app wallet and that, so far, no impact has been confirmed as originating from Descent’s hardware wallet itself.
On-chain analysis shows the attack was carried out in two main phases. The first attack began at 4:29 p.m. The attacker moved 9 XRP from a wallet with a balance of 10 XRP to a new address, then drained a total of 19,787 XRP from 204 wallets over about 14 minutes.
The initial automated script had a problem reflecting the XRP Ledger’s reserve structure properly. On the XRP Ledger, additional reserves are required not only for the base account reserve but also when holding additional objects such as trust lines. Because the attack tool did not calculate this properly, it failed to drain funds completely from some wallets. Failed attempts during the first attack phase totaled 72.
The attacker then changed tactics. The automated script was paused for about 33 minutes, and during that time the attacker moved funds directly from the top 12 wallets holding more than 42,000 XRP. Transfers continued at intervals of 10 to 30 seconds, and by 5:13 p.m. a total of 730,954 XRP had accumulated at a single new address. That was more than one-third of the total stolen amount. No additional fund movements were confirmed from that address afterward.
From 5:17 p.m., the revised automated script ran again. It was changed to calculate additional reserves for each account, and the attacker stole an additional 1,258,563 XRP from 1,336 wallets through 6:34 p.m. Processing speed reached about 17.6 accounts per minute.
The method of selecting targets also drew attention. The order of attacks showed a higher correlation with the order in which wallets were created than with wallet balances. Analysts assessed the correlation coefficient between attack order and wallet creation date at 0.65, while the coefficient with balances was only 0.09.
This suggests the attacker may have processed an already obtained wallet list in a fixed order rather than searching the XRP Ledger in real time to select wallets with large balances. Still, ledger records alone make it difficult to determine how the attacker obtained the private keys to the 1,552 wallets.
Money-laundering of the stolen funds also began while the attack was under way. At 6:25 p.m., while the second attack was in progress, more than 719,000 XRP was moved to a new address and then dispersed in small amounts. Among these, single-use wallets that sent 6,000 XRP each in 11 transfers were immediately absorbed into a separate laundering hub. These fund movements continued for about 4 hours, and part of the initially stolen funds was confirmed to have reached Binance at 8:18 p.m.
In the early hours of Sept. 16, 118,400 XRP was moved in 10 transfers through a cross-chain bridge service called Brijers. Around 5:30 a.m., multiple wallets for cashing out were consolidated into another laundering hub.
It was also noted that the laundering hub was not an address newly created for this attack. After it was created during a KuCoin withdrawal process on Aug. 9, it was already used for similar fund movements involving more than 1.36 million XRP. This suggests the attack may not have been the group’s first attempt at laundering, but a large-scale attack using existing infrastructure.
Most of the victim wallets were long-term user accounts created between 2021 and 2023. The most recently created wallet on the victim list was confirmed to have been created in March 2024, and newly created wallets made after that were not found among the victims.
Characteristics linked to a domestic user base also appeared in the initial funding routes. Binance accounted for the largest share as the exchange that supplied initial funds to about 15.7 percent of the victim wallets. Accounts activated through Coinone, Upbit and Bithumb were also found to make up nearly one-quarter of the victim wallets.
A significant portion of the funds is believed to remain under the attacker’s control after the theft. As of Sept. 16, about 1.8 million XRP of the roughly 2 million XRP stolen remained in attacker-controlled wallets, while the amount moved to exchanges or bridge services was about 236,000 XRP.
Descent is currently recommending that app-wallet users move their holdings to another safe wallet. The route of private-key exposure, the key issue in this case, has not yet been confirmed.
On-chain records confirmed so far show how the attacker moved and laundered the funds, but do not provide a direct answer on how the private keys for the 1,552 wallets were obtained. Until the cause of the private-key leak is identified, it is difficult to determine the precise compromise route of the attack and the possibility of additional damage.