DCENT Wallet is investigating unauthorized asset transfers linked to its software-based App Wallet after receiving the first user report on September 16. The company says the incident affects software wallets whose recovery phrases were exposed to the App Wallet signing environment, while no direct compromise of its hardware wallet products has been confirmed. DCENT is working with law enforcement, exchanges, security specialists and blockchain teams to trace and potentially freeze stolen assets.
According to DCENT’s official incident report, the current risk criteria include wallets that signed transactions using an App Wallet version earlier than 8.1.0, which was released on November 5, 2025. The relevant signing history can include coin transfers, token or NFT transfers, approvals and dApp transactions, and the potential scope extends across Bitcoin, Ethereum, XRPL, TRON and EVM-compatible networks.
Older App Wallet Signatures Define the Risk
The distinction between App Wallet and hardware mode is central to DCENT’s response. A hardware wallet remains outside the currently identified risk if its recovery phrase was generated and kept on the physical device and was never entered into the App Wallet. Simply connecting a DCENT hardware wallet to the mobile app to view balances or approve transactions does not expose its mnemonic to the phone.
The exception is any hardware wallet whose recovery phrase was later imported into the software wallet. Once the same mnemonic has been entered into the App Wallet, DCENT recommends abandoning that recovery phrase entirely and moving assets to addresses generated from a new one. Moving the old phrase onto another hardware device does not solve the problem because the same mnemonic recreates the same underlying keys.
In a technical security update, DCENT directed affected users to update the official app before migrating funds. The company’s FAQ specifies v10.0.0 or later for the migration process, while its deeper technical assessment identifies pre-v8.1.0 signing activity as the historical condition associated with potential exposure. Users are instructed to download updates only through official app stores.
Apologies for the inconvenience, have you tried to update your firmware which automatically upgrades your wallet security and functionality https://t.co/l0Z0eYJCME
— DCENT WALLET TEAM (@AskDcenteams) September 17, 2026
DCENT Traces Funds as Investigation Continues
DCENT has introduced an in-app checker to help users determine whether their wallet falls within the potentially affected group. The company is simultaneously tracing suspicious transfers and requesting freezes from exchanges and other counterparties, although it warns that recovery depends on blockchain activity, law-enforcement action and cooperation from third parties. No confirmed total loss figure has yet been published.
The incident adds to recent security problems affecting software-based crypto interfaces, including a security incident involving the Chimpers Card App and a fraudulent Ledger application that drained nearly 6 BTC. The incidents differ technically, but each illustrates how wallet security can fail outside the underlying blockchain itself through application, distribution or key-management layers.
DCENT is also warning users about secondary phishing attempts. The company says it does not operate official Telegram or Discord support channels and will never request a recovery phrase, private key or PIN, making unsolicited recovery assistance another potential threat while the investigation remains active. The next material update will be DCENT’s technical determination of the root cause, the final scope of affected addresses and whether any of the transferred assets can be recovered.
Natalie Pierce tracks the parts of crypto that move fast and rarely wait for everyone to catch up. From South Africa, she covers DeFi, AI crypto, hacks, airdrops, sentiment and emerging narratives, especially when user behavior and protocol risk start to overlap.
Her reporting is built for messy sectors. Natalie looks at incentives, reactions, security concerns, social momentum and early signs of traction without pretending every new trend is already proven. Her voice is clear and accessible, but careful enough for areas where excitement can outrun the facts very quickly.
