D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
If you hold crypto assets in the D'CENT app wallet, you should move them to a wallet with a new recovery phrase. On September 16, 2026, manufacturer IoTrust said it had identified suspicious asset transfers in that very app and is investigating the cause. On the company's account, the app wallet is what is affected. Anyone who uses only a hardware device and has never typed their words into the app has nothing to do, on the current state of information.
That single distinction carries the whole story, and most short news items leave it out. It decides whether you spend this evening making a handful of transactions or sleep soundly. This article explains how to tell which group you belong to, in what order to act, and which two follow-up steps tend to be left undone.
D'CENT App Wallet: What IoTrust Reported on September 16
The notice came through the company's official channel. It opens by stating that IoTrust has identified suspicious asset transfers related to the D'CENT App Wallet and is carrying out an urgent investigation. On the first findings, the problem is confined to the app wallet.
The company does not name a cause. It also names no number of affected wallets and no amount. That gap matters for judging the case: as long as the manufacturer itself puts no figure on the scale, every damage total in circulation is an assertion without a basis. The company says it will supply cause and scale through its official channels once both are established.
What is already established is the recommended action. IoTrust asks affected users to move their holdings as quickly as possible to a hardware wallet or another trusted address, to update the app to the current release, and to trigger no further transactions through the app wallet until that update is done. The company explicitly warns against following instructions from unofficial channels.
Why an Ongoing Investigation Is Not an All-Clear
An investigation whose outcome is still pending is the most uncomfortable state for users, because it offers no choice between right and wrong, only one between effort and risk. The effort of moving is manageable and one-off. The risk of waiting for the outcome is carried by the user alone, because holdings reachable through a compromised word list cannot be recovered after the fact.
Recovery Phrase: The One Question That Decides Whether You Are Affected
A recovery phrase, also called a seed phrase, is the list of usually 24 words from which every private key of a wallet, and with it full access to the holdings, can be derived mathematically. Whoever knows those words holds the funds, regardless of which device happens to be sitting in which drawer.
That is where the test question comes from, and it is not which device you own but where your words have already been entered. Three cases can be told apart cleanly.
Case one: you created a wallet directly in the app, with no hardware device. Your word list then sits in software, and you belong to the group addressed directly.
Case two: you own a hardware device but at some point also imported its word list into the app, perhaps for more convenient access to a balance. The same word list then exists in two places, and the recommendation applies to you as well, even though your device itself is not under suspicion.
Case three: you connect your hardware device to the app only to confirm transactions on the device, and you have never typed the words in. On the manufacturer's account so far, there is nothing for you to do.
The second case is the treacherous one, because it cannot be read off the hardware. It hangs on a decision many users made months ago and have long forgotten. If you are unsure, treat the import as having happened: the cost of an unnecessary precaution is a few network fees, and the cost of a false all-clear is the balance itself.
Biometric Wallet, D'CENT X and R3covery Card: Which Products the Notice Covers
The manufacturer runs several product lines, and the notice separates them. The app wallet is a pure software wallet in which the keys sit on the smartphone. Alongside it stand the hardware devices, among them the Biometric Wallet with a fingerprint sensor as well as the D'CENT X and D'CENT S models, where a separate security chip holds the keys and they never leave the device. The R3covery Card is a backup solution for the word list itself.
The company's statement refers to the app wallet. For the hardware devices, no exposure has been confirmed so far, by its own account. That is a careful formulation rather than an acquittal, and that is exactly how you should read it. The difference between a software wallet and a device with its own security chip is the reason the recommendation points toward hardware at all: a hardware wallet comparison shows which devices genuinely perform the signature inside the chip and which merely wrap a pretty shell around a software solution.

Withdrawing Funds From the App Wallet: The Order That Avoids Mistakes
The order matters more than the speed. A hasty transfer to an address whose word list you have not backed up in full turns a possible problem into a certain total loss.
First, prepare the destination. Create the target wallet before you move anything, and back up its word list completely and offline. Test the backup by restoring the wallet from the words once. How to store that backup so it survives a house fire and a change of address is something we have described in our guide to keeping a seed phrase safe.
Second, update the app. The manufacturer names release 10.0.0 or newer for Android and iOS as the minimum level and asks users to trigger no transactions through the app wallet before the update.
Third, transfer. Send a small amount first, check that it arrives in the target wallet, and move the rest afterwards. If you use several chains, work through them one at a time. Record fees and timestamps as you go; you will need them later for your tax return.
Fourth, retire the old word list. A word list that may have fallen into someone else's hands is never used again, not for a small remaining balance and not for a different chain. That word list is spent.
Hardware Wallets ComparedAn App Update Alone Is Not Enough: Why the Word List Has to Change
The most common mistake after a notice like this is to update the app and leave it at that. An update closes a gap in the software. What it does not do is make a word list secret again that may have been read out beforehand. If an attacker holds the 24 words, they no longer need the app at all: they can restore the wallet in any other software and clear out the balance from any device in the world.
For that reason the road back to safety always runs through a new word list and never through an update alone. The market went through the same mechanism with the Coldcard incident in August 2026, where it was likewise the regeneration of the words, not the new firmware, that ended the access.
Revoking Token Approvals: The Forgotten Step After a Wallet Change
A token approval is the permission you grant a smart contract once so that it may move a particular token from your address. That permission stays in place until you revoke it, and it is attached to the address, not to the wallet software.
An uncomfortable consequence follows. If you move your holdings to a new address but the old address still carries open approvals, any remainder that arrives there later stays exposed through those approvals. The addresses mainly affected are those on Ethereum and the networks built on it, because that is where the bulk of approvals are granted.
A revocation is an ordinary transaction and costs a network fee. In our analysis of September 14, 2026, that fee on Ethereum came to the equivalent of 0.52 cents per revocation, as we documented in our guide to revoking token approvals. At that price level there is no sensible reason to leave open approvals standing.
Self-Custody Wallets and MiCA: Why Germany's BaFin Has No Remit Here
For users in Germany, the supervisory position is the most important and at the same time the most awkward part. A self-custody wallet, also called a non-custodial wallet, is an application in which the user alone holds the private keys and the provider has no access to them.
That is precisely the constellation the European crypto regulation MiCA excludes from its scope. Merely manufacturing or distributing hardware and software for the custody of crypto assets does not fall under the licensing requirement, as long as the provider has no access to the assets or keys held. Only once a provider does have access to other people's keys does the product become a crypto service that needs authorisation.
For you as a user that means three things. There is no BaFin supervision over the maker of a pure self-custody wallet. There is no deposit guarantee or compensation mechanism to make good the losses. And there is no supervisory authority where you could report the incident with any prospect of redress. What remains are civil claims against a company based in South Korea, which is to say a theoretical route.
This legal position is shifting at a different point, and the difference is worth noting: new reporting obligations have applied to manufacturers since September 11, 2026, which we covered in our article on the reporting duty for wallet makers. Reporting duties improve the information available about incidents. A claim to compensation is not something they create.

Stolen Coins on Your Tax Return: What Section 23 EStG Does Not Give You
Anyone who loses crypto assets to theft regularly finds that the German tax office does not recognise the loss. The reason lies in the system: gains and losses on crypto assets held privately run through the private disposal transaction under Section 23 of the Income Tax Act, and a disposal transaction presupposes a sale or an exchange. A theft is neither, which is why the tax offices refuse to establish a loss even when it occurs inside the one-year holding period.
Whether such a loss can be claimed by another route, for instance as income-related expenses, is disputed among tax lawyers and depends heavily on the individual case. Anyone affected to a meaningful degree should discuss it with a tax adviser and not with a forum.
More important in practice is the move itself. A transfer between two of your own wallets is not a taxable event, because the beneficial owner does not change. In the data of many reporting tools it still looks like a disposal, and where the attribution is missing, the software may in the worst case compute a sale out of it. So document every one of today's transfers with date, amount, fee and both the source and the destination address, and flag them as your own transfer. Which programs merge several wallets cleanly is shown in our overview of crypto tax tools and portfolio trackers. Your acquisition data has to survive the move as well, or you lose the evidence for the holding period of your Bitcoin holdings.
Crypto Tax Tools and Portfolio TrackersPhishing After the Warning: How to Spot Fake Messages From the Maker
Every public security notice produces a second wave of attacks within hours that attaches itself to the first. The pattern is always the same: a message presents itself as help from the manufacturer, points to the genuine incident, and leads to a form asking for the recovery phrase. The manufacturer itself explicitly warns in its notice against following instructions from unofficial channels.
The rule against it is simple and admits no exception: no manufacturer, no support desk and no exchange ever asks for your 24 words. Every message that does is an attack, no matter how genuine the sender looks. That a sender address can be correct while the message is still forged is something we showed with the example of a phishing mail from the real sender domain.
For information, stick to the official company channel and to the manufacturer's support pages. Do not open links from direct messages, not even when they turn up in a group where you normally get reliable tips.
Open Questions in the Investigation: What Is Not Yet Settled
An honest assessment includes what the manufacturer has so far left open. Unknown are the cause of the suspicious transfers, the number of wallets affected, the size of the amounts moved and the exact period in which the transfers took place. It is equally unclear whether only certain releases of the app are affected or whether individual chains were more exposed than others.
As long as that is open, conclusions in either direction are off limits. A statement that the problem is contained and under control is as unproven as the claim of a sweeping breach. What is proven is the manufacturer's recommended action, and it stands regardless of how the investigation ends: anyone who had their words in the app moves.
Checking Your D'CENT App Wallet: What to Take Away
- First establish whether your word list was ever in the app. Only the app wallet and hardware devices with the same word list imported into the app are addressed. Anyone who connects their device solely to confirm transactions has nothing to do on the current state of information. Which devices genuinely perform the signature inside the security chip is something you can look up in the hardware wallet comparison.
- Move in the right order. Create the new wallet, back up the word list and test the backup by restoring from it, update the app, test with a small amount, then transfer the rest and retire the old word list for good. If you are changing software on the same occasion anyway, the software wallet comparison helps with the choice.
- Do the two steps that come after. Revoke the open token approvals on the old address, and document every transfer with date, amount, fee and both addresses so that your move does not show up as a sale on your tax return. A suitable program for that is among the crypto tax tools and portfolio trackers.
Sources: the notice from the @DCENTWALLETS account of September 16, 2026 as well as the manufacturer's questions and answers on the incident.
(As of September 17, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
- How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
- Restoring a Seed on Another Manufacturer's Wallet: What BIP39 Guarantees and What It Does Not
- How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
- Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
August 25, 2026 10:31 PM

Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.
October 2, 2026 10:36 AM

Hot Wallet or Cold Wallet: the Private Key Decides How Safe Your Coins Are
Hot wallet or cold wallet: the difference rests solely on whether the private key is online. What separates the two forms, where the limits of hardware lie and why moving to your own device triggers no tax.
September 10, 2026 9:13 AM

Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Trezor users received a fake STM32 entropy warning sent from a real Trezor address. Here is what happened and what to do if you clicked.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
July 31, 2026 3:54 PM

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
A firmware bug from March 2021 let an attacker drain $38 million from around 500 Bitcoin wallets. Here is what broke, who is exposed and what to do now.
August 21, 2026 4:27 PM

Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
On 19 August 2026 BaFin published two consumer notices on wallet offerings. Who controls the means of access decides whether an authorisation is needed.
September 14, 2026 10:13 AM

Revoke Token Approvals on Ethereum: A Revocation Now Costs 0.52 Cents
Every decentralized exchange, every lending pool and every bridge asks for a token approval, and it keeps running after the swap is done. We counted 5,910 approvals and worked out what a revocation really costs today.
August 21, 2026 4:17 PM

Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
Above €1,000 your provider has to establish whether the destination address really belongs to you. Article 14(5) of the transfer of funds regulation, five permitted methods, and the reason a withdrawal stalls without this step.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
September 30, 2026 7:16 AM

Tangem Wallet: The Card Without a Seed Phrase vs the Classic Hardware Wallet
The Tangem Wallet secures crypto with two or three identical cards instead of 24 words. What the sets cost, what the EAL6+ chip delivers and why losing every card is final.
September 28, 2026 10:26 AM

Phantom Wallet and Solscan: What a Solana Transfer Really Costs and Where It Fails
A transfer on Solana costs 0.000005 SOL, a new token account ties up 0.00148844 SOL once — both values measured on-chain by us today. This practical guide shows how to set up Phantom, how to get there from the exchange, how to read Solscan and what applies for tax in Germany.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
September 19, 2026 10:11 PM

North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers and Coding Tests
Seven agencies, among them Germany's BND and BfV, warn about the WaterPlum group: 30,000 infected machines, more than 7,000 drained wallets. The bait is a job offer, the trap a coding test.
August 25, 2026 10:11 PM

Ledger Closes a Gap in the Ethereum App: When the Display Shows Something Other Than What You Sign
Ledger has closed a flaw in its Ethereum app that let a malicious application swap the reviewed transaction for a different one. Anyone holding Ether or ERC-20 tokens on the device should check the app version and clear out old token approvals.
August 23, 2026 4:36 PM

Operation ASTERIX: How a Fake Support Call Delivers a Counterfeit Wallet App
Security researchers analysed an open server on which a phone system, phishing interfaces and cloned wallet programs all came together. The largest list of numbers was the German one.
August 20, 2026 1:45 AM

Wallet Drainers: What You Really Approve When You Confirm, and How to Take It Back
Most emptied wallets were never hacked. Their owners confirmed it themselves, granting an approval that is unlimited and never expires. What sits behind "Approve" and a signature request, and how to get rid of old approvals.
October 2, 2026 4:32 AM

NEAR Intents halts withdrawals after a $3.8 million exploit: here are the reasons
NEAR Intents confirms an exploit of more than $3.8 million and holds deposits and withdrawals on eleven networks. Reimbursement is promised, a date for it is not.
August 22, 2026 4:13 AM

SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
SafePal confirmed a data breach on August 16, 2026: the names, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases and private keys were not affected, but the phishing risk is substantial.
August 20, 2026 4:20 AM

Crypto Exchange Delisting: What Happens to Your Tokens When Trading and Withdrawals Close
A delisting runs in four stages, and only one of them is genuinely dangerous: the end of the withdrawal deadline. Using two live OKX dates as the example, we show what happens at each stage and how to tell whether it affects you.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
August 4, 2026 1:21 PM

Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
A fourth wave of Coldcard sweeps took another 449 BTC on Monday, yet Bitcoin climbed back toward $64,000. Here is what changed and who is still exposed.
September 16, 2026 7:39 PM

Deutsche Bank to Custody Bitcoin and Ether: Why Retail Clients Are Missing and What to Check in Your Own Custody
Deutsche Bank will custody Bitcoin, Ether and three stablecoins, but addresses corporates and institutions only. What the launch under supervisory reservation means, and the four questions you should put to any custody arrangement.
September 16, 2026 1:28 PM

Crypto Withdrawal to Your Own Wallet: Ten Providers Checked, Three Will Not Let Your Coins Out
Seven of ten providers available in Germany offer a payout to a wallet address you control yourself; three do not. Our survey of September 16, 2026, shows how to spot the difference before you buy, and why the question matters right now.
August 31, 2026 7:20 AM

Browser Extensions as Wallet Thieves: How a Sports App Became a Seed Phrase Collector
In August 2026 the security firm Socket disclosed two separate campaigns: 40 confirmed malicious Firefox extensions and 19 for Chrome and Edge, all of them from the official marketplaces. Nine of them were harmless sports apps that only turned into wallet thieves through an update.
September 20, 2026 4:15 PM

Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
After every major data breach, the number of phishing emails sent in the name of crypto exchanges and wallet manufacturers rises. This article shows you how to recognise such a message, which data a reputable provider never requests by email, and what to do in the first hour after a click.
August 31, 2026 10:14 PM

Trust Wallet Drops 25 Networks: What Users Should Know After September 15
Recap as of September 27, 2026: Trust Wallet had announced it would remove built-in support for 25 blockchain networks from its app on September 15, 2026, among them MultiversX, Polygon zkEVM and Moonbeam. Your coins stay yours, the convenient access does not: this article shows how to add a chain by hand and for which nine networks that route is not open.
More from CryptoTicker
