← Radar

Incident case file

Sign in to watch

DCENT App Wallet Unauthorized Transfers — $6.57M (Single-Source Estimate)

Incident date Sep 15, 2026Last updated Sep 24, 2026

0 views

ActiveBitcoinEthereumXRPLTRONEVMApp wallet signing compromise — vector undisclosedCluster: DCENT-MULTI-2026-09

Estimated loss

$6.6M

Affected users

Number of affected users is not confirmed
Group joining is coming soon.

Investigation

35%

Facts and investigation

Ledger

Attacker

TODO

Funds moved to

TODO — DCENT/IoTrust has stated it is tracing stolen funds with an external security team and has requested exchange freezes, but has not published destination addresses.

Linked

No attacker or consolidation addresses have been publicly disclosed. Exposure criteria per DCENT's own status report: recovery phrase entered into the App Wallet at any point, a prior signing history, signing performed on an app version earlier than 8.1.0 (released Nov 5, 2025), and one of Bitcoin, Ethereum, XRPL, TRON or other EVM-based chains.

Chronology

1 beat
  1. On September 16, 2026 (KST), DCENT (formerly D'CENT), a digital asset platform built by IoTrust, detected abnormal asset transfers linked to its software App Wallet and issued an urgent public notice. The company's official September 17 status report confirmed it is working with law enforcement, security specialists and exchanges to trace and potentially freeze the funds, and is conducting a technical root-cause analysis, but explicitly declined to disclose technical details, stating that doing so could enable identical or similar attacks. Exposure was defined by four criteria: a recovery phrase ever entered into the App Wallet (including via hardware-to-app or app-to-hardware transfer), a history of signing transactions, signing having occurred on an app version prior to 8.1.0, and use on Bitcoin, Ethereum, XRPL, TRON, or other EVM-based chains — including token transfers across multiple EVM chains sharing the same underlying key. Hardware wallets themselves were not confirmed as directly compromised. The only quantified loss figure, $6.57 million, comes from a single source (SlowMist) and has not been independently corroborated or confirmed by DCENT itself. Users were advised to migrate to a newly generated seed phrase rather than merely updating the app.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)