D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?

Table of Contents
Table of Contents
If you hold crypto assets in the D'CENT app wallet, you should move them to a wallet with a new recovery phrase. On September 16, 2026, manufacturer IoTrust said it had identified suspicious asset transfers in that very app and is investigating the cause. On the company's account, the app wallet is what is affected. Anyone who uses only a hardware device and has never typed their words into the app has nothing to do, on the current state of information.
That single distinction carries the whole story, and most short news items leave it out. It decides whether you spend this evening making a handful of transactions or sleep soundly. This article explains how to tell which group you belong to, in what order to act, and which two follow-up steps tend to be left undone.
D'CENT App Wallet: What IoTrust Reported on September 16
The notice came through the company's official channel. It opens by stating that IoTrust has identified suspicious asset transfers related to the D'CENT App Wallet and is carrying out an urgent investigation. On the first findings, the problem is confined to the app wallet.
The company does not name a cause. It also names no number of affected wallets and no amount. That gap matters for judging the case: as long as the manufacturer itself puts no figure on the scale, every damage total in circulation is an assertion without a basis. The company says it will supply cause and scale through its official channels once both are established.
What is already established is the recommended action. IoTrust asks affected users to move their holdings as quickly as possible to a hardware wallet or another trusted address, to update the app to the current release, and to trigger no further transactions through the app wallet until that update is done. The company explicitly warns against following instructions from unofficial channels.
Why an Ongoing Investigation Is Not an All-Clear
An investigation whose outcome is still pending is the most uncomfortable state for users, because it offers no choice between right and wrong, only one between effort and risk. The effort of moving is manageable and one-off. The risk of waiting for the outcome is carried by the user alone, because holdings reachable through a compromised word list cannot be recovered after the fact.
Recovery Phrase: The One Question That Decides Whether You Are Affected
A recovery phrase, also called a seed phrase, is the list of usually 24 words from which every private key of a wallet, and with it full access to the holdings, can be derived mathematically. Whoever knows those words holds the funds, regardless of which device happens to be sitting in which drawer.
That is where the test question comes from, and it is not which device you own but where your words have already been entered. Three cases can be told apart cleanly.
Case one: you created a wallet directly in the app, with no hardware device. Your word list then sits in software, and you belong to the group addressed directly.
Case two: you own a hardware device but at some point also imported its word list into the app, perhaps for more convenient access to a balance. The same word list then exists in two places, and the recommendation applies to you as well, even though your device itself is not under suspicion.
Case three: you connect your hardware device to the app only to confirm transactions on the device, and you have never typed the words in. On the manufacturer's account so far, there is nothing for you to do.
The second case is the treacherous one, because it cannot be read off the hardware. It hangs on a decision many users made months ago and have long forgotten. If you are unsure, treat the import as having happened: the cost of an unnecessary precaution is a few network fees, and the cost of a false all-clear is the balance itself.
Biometric Wallet, D'CENT X and R3covery Card: Which Products the Notice Covers
The manufacturer runs several product lines, and the notice separates them. The app wallet is a pure software wallet in which the keys sit on the smartphone. Alongside it stand the hardware devices, among them the Biometric Wallet with a fingerprint sensor as well as the D'CENT X and D'CENT S models, where a separate security chip holds the keys and they never leave the device. The R3covery Card is a backup solution for the word list itself.
The company's statement refers to the app wallet. For the hardware devices, no exposure has been confirmed so far, by its own account. That is a careful formulation rather than an acquittal, and that is exactly how you should read it. The difference between a software wallet and a device with its own security chip is the reason the recommendation points toward hardware at all: a hardware wallet comparison shows which devices genuinely perform the signature inside the chip and which merely wrap a pretty shell around a software solution.

Withdrawing Funds From the App Wallet: The Order That Avoids Mistakes
The order matters more than the speed. A hasty transfer to an address whose word list you have not backed up in full turns a possible problem into a certain total loss.
First, prepare the destination. Create the target wallet before you move anything, and back up its word list completely and offline. Test the backup by restoring the wallet from the words once. How to store that backup so it survives a house fire and a change of address is something we have described in our guide to keeping a seed phrase safe.
Second, update the app. The manufacturer names release 10.0.0 or newer for Android and iOS as the minimum level and asks users to trigger no transactions through the app wallet before the update.
Third, transfer. Send a small amount first, check that it arrives in the target wallet, and move the rest afterwards. If you use several chains, work through them one at a time. Record fees and timestamps as you go; you will need them later for your tax return.
Fourth, retire the old word list. A word list that may have fallen into someone else's hands is never used again, not for a small remaining balance and not for a different chain. That word list is spent.
Hardware Wallets ComparedAn App Update Alone Is Not Enough: Why the Word List Has to Change
The most common mistake after a notice like this is to update the app and leave it at that. An update closes a gap in the software. What it does not do is make a word list secret again that may have been read out beforehand. If an attacker holds the 24 words, they no longer need the app at all: they can restore the wallet in any other software and clear out the balance from any device in the world.
For that reason the road back to safety always runs through a new word list and never through an update alone. The market went through the same mechanism with the Coldcard incident in August 2026, where it was likewise the regeneration of the words, not the new firmware, that ended the access.
Revoking Token Approvals: The Forgotten Step After a Wallet Change
A token approval is the permission you grant a smart contract once so that it may move a particular token from your address. That permission stays in place until you revoke it, and it is attached to the address, not to the wallet software.
An uncomfortable consequence follows. If you move your holdings to a new address but the old address still carries open approvals, any remainder that arrives there later stays exposed through those approvals. The addresses mainly affected are those on Ethereum and the networks built on it, because that is where the bulk of approvals are granted.
A revocation is an ordinary transaction and costs a network fee. In our analysis of September 14, 2026, that fee on Ethereum came to the equivalent of 0.52 cents per revocation, as we documented in our guide to revoking token approvals. At that price level there is no sensible reason to leave open approvals standing.
Self-Custody Wallets and MiCA: Why Germany's BaFin Has No Remit Here
For users in Germany, the supervisory position is the most important and at the same time the most awkward part. A self-custody wallet, also called a non-custodial wallet, is an application in which the user alone holds the private keys and the provider has no access to them.
That is precisely the constellation the European crypto regulation MiCA excludes from its scope. Merely manufacturing or distributing hardware and software for the custody of crypto assets does not fall under the licensing requirement, as long as the provider has no access to the assets or keys held. Only once a provider does have access to other people's keys does the product become a crypto service that needs authorisation.
For you as a user that means three things. There is no BaFin supervision over the maker of a pure self-custody wallet. There is no deposit guarantee or compensation mechanism to make good the losses. And there is no supervisory authority where you could report the incident with any prospect of redress. What remains are civil claims against a company based in South Korea, which is to say a theoretical route.
This legal position is shifting at a different point, and the difference is worth noting: new reporting obligations have applied to manufacturers since September 11, 2026, which we covered in our article on the reporting duty for wallet makers. Reporting duties improve the information available about incidents. A claim to compensation is not something they create.

Stolen Coins on Your Tax Return: What Section 23 EStG Does Not Give You
Anyone who loses crypto assets to theft regularly finds that the German tax office does not recognise the loss. The reason lies in the system: gains and losses on crypto assets held privately run through the private disposal transaction under Section 23 of the Income Tax Act, and a disposal transaction presupposes a sale or an exchange. A theft is neither, which is why the tax offices refuse to establish a loss even when it occurs inside the one-year holding period.
Whether such a loss can be claimed by another route, for instance as income-related expenses, is disputed among tax lawyers and depends heavily on the individual case. Anyone affected to a meaningful degree should discuss it with a tax adviser and not with a forum.
More important in practice is the move itself. A transfer between two of your own wallets is not a taxable event, because the beneficial owner does not change. In the data of many reporting tools it still looks like a disposal, and where the attribution is missing, the software may in the worst case compute a sale out of it. So document every one of today's transfers with date, amount, fee and both the source and the destination address, and flag them as your own transfer. Which programs merge several wallets cleanly is shown in our overview of crypto tax tools and portfolio trackers. Your acquisition data has to survive the move as well, or you lose the evidence for the holding period of your Bitcoin holdings.
Crypto Tax Tools and Portfolio TrackersPhishing After the Warning: How to Spot Fake Messages From the Maker
Every public security notice produces a second wave of attacks within hours that attaches itself to the first. The pattern is always the same: a message presents itself as help from the manufacturer, points to the genuine incident, and leads to a form asking for the recovery phrase. The manufacturer itself explicitly warns in its notice against following instructions from unofficial channels.
The rule against it is simple and admits no exception: no manufacturer, no support desk and no exchange ever asks for your 24 words. Every message that does is an attack, no matter how genuine the sender looks. That a sender address can be correct while the message is still forged is something we showed with the example of a phishing mail from the real sender domain.
For information, stick to the official company channel and to the manufacturer's support pages. Do not open links from direct messages, not even when they turn up in a group where you normally get reliable tips.
Open Questions in the Investigation: What Is Not Yet Settled
An honest assessment includes what the manufacturer has so far left open. Unknown are the cause of the suspicious transfers, the number of wallets affected, the size of the amounts moved and the exact period in which the transfers took place. It is equally unclear whether only certain releases of the app are affected or whether individual chains were more exposed than others.
As long as that is open, conclusions in either direction are off limits. A statement that the problem is contained and under control is as unproven as the claim of a sweeping breach. What is proven is the manufacturer's recommended action, and it stands regardless of how the investigation ends: anyone who had their words in the app moves.
Checking Your D'CENT App Wallet: What to Take Away
- First establish whether your word list was ever in the app. Only the app wallet and hardware devices with the same word list imported into the app are addressed. Anyone who connects their device solely to confirm transactions has nothing to do on the current state of information. Which devices genuinely perform the signature inside the security chip is something you can look up in the hardware wallet comparison.
- Move in the right order. Create the new wallet, back up the word list and test the backup by restoring from it, update the app, test with a small amount, then transfer the rest and retire the old word list for good. If you are changing software on the same occasion anyway, the software wallet comparison helps with the choice.
- Do the two steps that come after. Revoke the open token approvals on the old address, and document every transfer with date, amount, fee and both addresses so that your move does not show up as a sale on your tax return. A suitable program for that is among the crypto tax tools and portfolio trackers.
Sources: the notice from the @DCENTWALLETS account of September 16, 2026 as well as the manufacturer's questions and answers on the incident.
(As of September 17, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Cypher Shutdown: Withdraw Your Balance Before the September 6 Deadline
- How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
- Restoring a Seed on Another Manufacturer's Wallet: What BIP39 Guarantees and What It Does Not
- Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
- Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase






























