# protocol exploit — X 热门讨论 (2026-09-25 17:50 UTC)

## @HatomProtocol (Hatom Labs) · 09-25 16:59 · ♥44 ↻12 💬1 Postmortem on Mex Money Market Exploit : https://x.com/HatomProtocol/status/2103529959482409115

## @martypartymusic (MartyParty) · 09-25 14:22 · ♥38 ↻1 💬14 Ongoing attack of the DCent XRP Wallet

On-chain tracking shows the D’CENT App Wallet drain is still active as of 25 September 2026. It is not an XRP Ledger protocol exploit. Attackers used valid signatures from already-compromised keys.

First wave: 15 September 2026 (manual large wallets + automated script). Six main waves through 20 September, then continued smaller sweeps. Latest tally cited: ~12.4 million XRP from 7,393 wallets, plus thousands of account deletions to collect remaining reserves. ~6.3 million XRP swapped toward Ethereum via THORChain; other flows to exchanges/bridges . A portion remained in operator-controlled wallets as of 25 Sep.

Numbers in earlier articles (~2M then ~11.7M XRP / 6,678 wallets) were snapshots; later waves and deletions increased the total. Some emptied addresses were later refilled and drained again do not send XRP back to an old App Wallet address.

D’CENT (IoTrust) says the issue is limited to the software App Wallet, not standalone hardware (D’CENT X / S / biometric) unless that hardware recovery phrase was ever entered or restored into the App Wallet.

Their published risk criteria (subject to update):

Recovery phrase was at some point entered into the App Wallet. The address has a signing history (sends, tokens, NFTs, approvals, dApps). Signing happened on an app version earlier than 8.1.0 (released 5 Nov 2025). Version at signing time matters, not current install. Chains include XRPL, Bitcoin, Ethereum, TRON, and other EVM networks. Same key can apply across EVM chains and to tokens like USDT.

Root cause has not been published in technical detail (they say disclosure could enable copycats). Investigation is with Korean law enforcement plus exchanges and analysts; freezing/recovery is not guaranteed. What users should do

Official guidance:

Update the app only from official App Store / Google Play. Create a wallet with a new recovery phrase (do not restore the old one it can regenerate the same or related keys). Move all assets: coins, tokens, NFTs, stakes, and revoke approvals. Never reuse the old address for deposits or anything else. Hardware-only users who never imported the phrase into the App Wallet: no extra action based on what D’CENT has confirmed so far. https://x.com/martypartymusic/status/2103490301880844625

## @immutablejacob (Jake Koch-Gallup) · 09-25 14:41 · ♥28 ↻4 💬8 can zcash really flip bitcoin?

as someone with a large $BTC position and zero zcash:native, i had to find out.

in 2010, satoshi wrote that a privacy-preserving solution would make a much better implementation of bitcoin. he just couldn't figure out how to prove a coin hadn't been spent without revealing it.

@zcash solved that with ZK proofs. BCH, BSV, and XEC also pitched themselves as upgraded bitcoin, but none of them built privacy into the protocol, and none came close to BTC.

zcash:native went from 0.05% of BTC's market cap at the start of 2025 to 1.49% today.

> ETH: 19.4% of BTC > BNB: 6.1% > XRP: 5.7% > ZEC: 1.49%

a rerating to BNB and XRP levels is roughly a 4x.

the bull case: > shielded ZEC hit a record 5.2m in may > privacy coins are still only ~1.2% of the crypto market > zcash has the same 21m cap and halving schedule as bitcoin > @grayscale's zcash ETF pulled in $293m of net inflows in its first month

Zcash's newest competitor is shielded bitcoin, a paper from @allocinitxyz that brings private transfers to bitcoin without a soft fork.

more privacy on bitcoin is great, but it's still a paper that needs a trusted setup, and privacy needs a crowd to hide in. zcash already has millions of ZEC shielded.

the bear case: > only ~29% of ZEC is actually shielded > ~4% annual inflation, with 20% of block rewards going to dev funds > a four-year-old counterfeiting bug in its main shielded pool was found in may (patched, no evidence of exploit) > privacy keeps arriving on bigger chains via tech like @RAILGUN_Project and @zama

it won't flip bitcoin, but it can get a lot closer. i am still sidelined for now.

full breakdown in today's @blockworksres newsletter: https://t.co/k0v9O6WhNl https://x.com/immutablejacob/status/2103495055147241546