Buy now

On 16 September 2026, IoTrust, the Korean company behind the D'CENT brand, posted an urgent notice saying it had detected abnormal asset transfers involving the D'CENT App Wallet and had opened an emergency investigation. If you own a D'CENT cold wallet and you've never touched the app wallet, the company's early read is that this doesn't reach you. The instruction it gave to one specific group of hardware owners is the part worth understanding, because the reasoning behind it applies well beyond this brand.

What the company has said, and what it hasn't

IoTrust's preliminary finding is that the problem appears limited to the D'CENT App Wallet, the software product, rather than the hardware line. Three things remain open: the root cause of the transfers, the full scope of who and what was affected, and what response measures will follow. None of those had been settled publicly at the time of writing, which means anything you read confidently explaining how this happened is ahead of the evidence.

Alongside the notice came an instruction to move assets immediately to a secure hardware wallet or another trusted address, and it covered two groups. Anyone holding funds in the app wallet is the obvious one. Second, and this is the group that matters here, anyone using the same recovery words in both the D'CENT App Wallet and a D'CENT hardware wallet.

At least one user has described being drained overnight through transactions they never approved, saying they had not knowingly shared their recovery words with anyone. We'd treat individual accounts as unconfirmed until the investigation reports, though the pattern being described is consistent with keys being reachable somewhere other than the device.

Why a hardware owner would be told to move funds at all

Here is the mechanism, and it isn't specific to D'CENT. A hardware wallet protects you because the key is generated inside a chip and never leaves it, so a compromised phone or laptop has nothing to copy. That protection describes the key's location. It says nothing about copies of the same key living somewhere else.

When you import your recovery phrase into a software wallet, whether for convenience, to check a balance, or because an onboarding flow suggested it, you create a second copy of that key inside an environment with a completely different threat profile. Both wallets now control the same coins. Your security is set by the weaker of the two, and the hardware device cannot help you, because nothing is wrong with the hardware. The attacker never goes near it.

That's why the notice reads the way it does. Owning the cold wallet isn't the question; whether its recovery words were ever typed into the app is.

What to do if this describes your setup

Assume the phrase is exposed and act on that basis rather than waiting for the investigation. Generate a new wallet with a fresh recovery phrase on a device you trust, move your funds to the new addresses, and retire the old phrase entirely. A phrase that may have been copied is worth nothing to you as a secret from that point forward, and the coins are the only thing you can still control.

Do the migration in one sitting on a machine you trust, verify each receiving address on the device screen before sending, and start with a small test transaction. If the exposed wallet holds tokens with active approvals attached, revoke those too.

How this compares to the incidents around it

2026 has produced several wallet stories that get flattened into the same headline and shouldn't be. The Coldcard exploit was a firmware defect in how seeds were generated, which reached coins sitting on hardware that had done nothing wrong. The Trezor and ShipMonk breaches exposed customer names and addresses through third parties, creating a phishing and burglary problem rather than a key problem. This one, on the current evidence, sits in a third category: a software product's failure that reaches hardware owners only through a phrase they chose to share between the two.

Those three need different responses, and lumping them together as "hardware wallets got hacked" leaves people doing the wrong thing. We wrote about the four ways a cold wallet can be compromised if you want the full taxonomy.

The design question underneath, and what your recovery should look like

The habit that created this exposure is one the industry built in. Almost every wallet hands you twelve or twenty-four words and treats them as portable, which they are, and that portability is exactly what lets a private key end up in three places you've half forgotten. A backup you can type anywhere is a backup you can leak anywhere.

TapSafe Recovery is our answer to that. Recovery splits across a Recovery Tag holding half of what's required and your paired phone holding the other half, encrypted into your own iCloud or Google Drive rather than sitting on the handset, with optional Recovery Contacts holding a quarter each and seeing nothing about your balances. Built on a custom implementation of Shamir's Secret Sharing, it restores by tapping objects together, so the normal path back into your wallet never involves typing words into a screen. The BIP-39 seed phrase stays available on-device as a last resort, which keeps you free to leave for other hardware, and keeps the reveal a deliberate act rather than a routine one.

On the Ryder One the key is created inside an EAL6+ certified Infineon SLC38 and never leaves it, the device speaks over NFC alone with no USB, Bluetooth or Wi-Fi, and every transaction is drawn in full on the 1.6-inch AMOLED screen before a button wired directly to the chip signs it. The firmware has been independently audited by Halborn.

The short version

Watch for IoTrust's findings before drawing conclusions about what failed. Meanwhile, if your hardware wallet's recovery words have ever been entered into a phone app, any brand, any reason, that is the exposure worth closing today. Setup on the Ryder One runs three taps and under a minute, and the Starter Combo is 149 USD with the Recovery Tag, wireless charger and pouch included. Get your Ryder One.


Meta description: A D'CENT cold wallet owner was told to move funds after the app wallet incident. Why a shared recovery phrase undoes hardware security, and what to do now.

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More