On 16 September 2026, DCENT Wallet — the South Korea product from IoTrust — posted that it had seen abnormal asset transfers tied to the DCENT App Wallet and was investigating. The practical instruction was blunt: if your coins sit in that hot wallet, or you reused its mnemonic on a hardware device, move them. Cause and loss size were not published in that first notice. That gap is where phishing crews work.
This is not a recap of DCENT’s thread. It is a decision tree for anyone holding crypto in a phone app while a vendor is still investigating, plus the TrustGhost checks that stop a “rescue” from becoming a second drain.
What DCENT actually said
The company said initial findings pointed at the App Wallet, not every DCENT product. It told users to transfer assets to a secure hardware wallet or another trusted address if either of these is true: you hold any amount in the DCENT App Wallet, or you use the same mnemonic on the app and a hardware wallet. In a follow-up, it told people who only connect the hardware device and never entered the phrase in the app that they did not need to move. It also warned against impersonation and said further details would come through official channels.
Read that as a vendor drawing a line between a software hot wallet and a device that never leaked its seed into an app. Until a postmortem names the bug, treat the line as a working hypothesis, not a guarantee. Do not wait for a dollar figure before you move funds that still sit in the app.
Who should move funds, and who should not panic-send
- Coins in the DCENT App Wallet: move them. Amount does not matter. A small balance is still a live key.
- Same seed in the app and on a hardware wallet: move everything off that seed. The hardware box does not cancel a phrase that already lived in software.
- Hardware only, seed never typed into the app: DCENT said no action. Keep the firmware and cable habits you already use. Ignore DMs that claim otherwise.
- You already sent to a “support” address this week: stop. That destination is the incident now, not DCENT’s app.
The common mistake after a wallet alert is to copy the first destination that looks official. The alert did not publish a sweep address. Anyone offering one is not helping you migrate.
How to migrate without feeding a second scam
Generate the new wallet first, on hardware or a fresh install you control, then send. Do not create the new seed inside the same compromised app if you can avoid it. Write the new phrase offline. Send a tiny test, confirm on an explorer, then move the rest.
- Open only DCENT’s known site or app store listing if you need their wording. Do not follow links from Telegram, email, or X replies.
- Paste the destination you created into TrustGhost’s wallet lookup before the full transfer. A brand-new empty address is normal. An address already reported for phishing is not.
- If a helper asks you to “verify” by connecting a wallet or signing a permit, that is a drainer. A move is a send you initiate, not a signature on their site.
- After the move, that old app seed is retired. Do not import it elsewhere “just to check.”
Why a shared seed makes hardware useless
A hardware wallet stores keys in a chip. It cannot unsay a mnemonic you also typed into a phone. If the App Wallet path can sign, every chain derived from that phrase can move. That is why DCENT grouped seed reuse with “funds currently in the app.” The hardware unit is still a good destination for a new phrase. It is not a shield for the old one.
If you were already drained
Sweep leftovers to a new seed. Revoke token approvals from a computer you trust, not from a “recovery” dapp that messaged you. Report the receiving address and the transaction hash on TrustGhost so the next lookup is not a rumor. File the same hash with your local cyber unit or IC3 if you want a law-enforcement record. None of that reverses the block. It stops the next person from treating that wallet as a safe invoice.
Recovery specialists who appear in your mentions after a vendor alert are a second market. They quote a percentage, ask for a prepayment, and often drain the replacement wallet. Independent company reviews and a wallet report beat a stranger with a countdown.
What is still unknown
As of the 16 September notice, DCENT had not published a root cause, a list of affected versions, or a confirmed loss total. This article does not invent those numbers. Watch DCENT’s official accounts for the investigation, and treat every unofficial “fix APK,” seed checker, or whitelist form as hostile until the company names it. If you use other hot wallets, the lesson still travels: a software mnemonic is a hot key, and a panic move is when drainers convert fear into a signature.
FAQ
- Was the DCENT hardware wallet hacked?
- DCENT’s first public finding was that abnormal transfers involved the DCENT App Wallet, not a blanket hardware compromise. If you only connected the device and never typed the seed phrase into the app, DCENT said no action is needed. That can still change if the investigation finds a wider issue, so watch official channels only.
- I used the same seed in the DCENT app and a hardware wallet. What now?
- Treat both as burned. Create a new wallet on a device that never saw the old phrase, then send remaining assets there. A hardware wallet cannot protect a seed you also pasted into a phone app.
- Should I send coins to an address someone DMs me after this alert?
- No. Vendor emergencies are when impersonators send “migration” addresses and fake support links. Only use a destination you generated yourself, on hardware you control, after checking the address on TrustGhost and in an explorer.
- What if I already got drained from the DCENT App Wallet?
- Move whatever is left to a new seed. Do not send a recovery fee to anyone who messaged you. Report the destination address and transaction hash as a scam wallet so the next person can look it up before they pay it.
