TL;DR
- DCENT detected anomalous transfers in its App Wallet and urgently asked users to move their assets immediately.
- The company indicated that the issue appears to be limited to the App Wallet and that users who only connected their device without entering the seed phrase do not need to take action.
- As the investigation progresses, DCENT warned its users to remain alert to impersonation and phishing attempts.
The South Korean hardware wallet manufacturer DCENT, developed by IoTrust Co., Ltd., issued a critical security alert on its official X account.
The team reported having detected anomalous asset transfers linked to the DCENT App Wallet and asked its users to transfer their funds “as soon as possible to a secure hardware wallet or another trusted address”.
Important Notice
We have detected abnormal asset transfers involving the DCENT App Wallet and are currently conducting an urgent investigation.
Based on our initial findings, the issue appears to be limited to the DCENT App Wallet.
If either of the following applies to you, we… pic.twitter.com/dhDZjmnh9S
— DCENT Wallet (@DCENTWALLETS) September 16, 2026
DCENT Is Unaware of the Full Extent of the Problem
According to the published information, the incident would affect those who hold assets in the App Wallet, regardless of the amount, and also those who use the same mnemonic phrase in both the App Wallet and a hardware wallet.
However, the company clarified that users who only connected their device without having entered the phrase in the application do not need to take any action. The cause and exact scope of the problem have not yet been confirmed.
IoTrust Co., Ltd. was founded by security experts with experience in Secure Element (SE) and Trusted Execution Environment (TEE) technologies, which makes an incident of this nature particularly striking for the community. The company indicated that it prioritizes the investigation and will provide updates through its official channels once the cause, the scope of the impact, and additional response measures are confirmed.
A String of On-chain Incidents
The DCENT incident adds to a string of security events that have marked recent weeks. Payment processor Swiss Bitcoin Pay revealed that a user infiltrated its internal systems, forcing the company to temporarily shut down its operations. In addition, the bitcoin bridge of Symbiosis was exploited, Nomic‘s nBTC lost its backing, and the BTC reserves of Liquid Network were partially drained. Although Liquid Network managed to recover a portion of the funds, the attackers retained approximately 600 BTC.
DCENT reiterated to its users to remain vigilant against phishing and impersonation attempts, and to only follow instructions coming from its verified official channels.




