DCENT, a crypto wallet brand operated by IoTrust, has warned users about abnormal asset transfers from its App Wallet. The company said it found unusual transfers on September 16, 2026, and started an urgent investigation.
The alert has raised concern across the crypto community because the exact cause is still unknown. DCENT has also not confirmed the full number of affected wallets or the final value of assets at risk.
At this stage, the company says its first checks point to the App Wallet, which is the software wallet inside the DCENT mobile app. There is no confirmed evidence that the DCENT hardware wallets themselves were affected.
Security researchers have placed the estimated loss at about $6.57 million. SlowMist lists the amount as $6.57 million and says the attack method remains unknown. This figure should be treated as an estimate, not as a final loss number confirmed by DCENT.
What DCENT Has Confirmed So Far
DCENT’s first public notice said it had detected abnormal asset transfers tied to the App Wallet. The company said it was carrying out an emergency investigation to understand what had happened.
Its early findings point to a problem with the App Wallet rather than the hardware wallet itself. DCENT has not yet given a confirmed explanation for how the abnormal transfers took place.
The company has also not confirmed the total number of users who may have lost funds. It has not provided a final figure for the total assets affected.
This makes the current $6.57 million figure important, but also limited. It comes from security research and blockchain tracking rather than a final loss statement from DCENT.
Who May Need to Act
DCENT has asked users with funds in its App Wallet to take action as soon as possible.
The warning also covers people who use the same mnemonic phrase for both their App Wallet and a hardware wallet. A mnemonic phrase is the recovery phrase that can restore access to a crypto wallet.
This detail matters because a hardware wallet can remain physically safe while its recovery phrase may still face risk if that same phrase was placed into an App Wallet.
DCENT has said that users who share one recovery phrase between the two wallet types should take action. The company has also made clear that the risk does not depend on which wallet first created the recovery phrase.
Hardware Wallets Are Not Confirmed Affected
One of the most important points in the case is the difference between DCENT’s App Wallet and its hardware wallet products.
DCENT has said that, so far, it has not confirmed any impact from its hardware wallets themselves. This means there is no current confirmation that a hardware wallet alone has suffered the same problem.
DCENT has also given different advice based on how users set up their wallets. A person who uses only a DCENT hardware wallet and has never entered or restored that wallet’s recovery phrase inside the App Wallet does not fall under the same warning.
However, anyone who imported a hardware wallet’s recovery phrase into the App Wallet needs to pay close attention to the company’s advice.
Why the Recovery Phrase Matters
A recovery phrase is one of the most important pieces of information in a crypto wallet. It can restore access to the wallet and its assets.
DCENT’s own help center says its wallets are non-custodial. This means DCENT does not hold users’ crypto for them. The assets exist on the blockchain, while the wallet holds the private information needed to control those assets.
If another person gets access to a recovery phrase, that person may be able to restore the wallet elsewhere and move the assets.
For this reason, users should never share their recovery phrase with another person, even if that person claims to work for DCENT.
DCENT says it will never ask users for their recovery words, private key, PIN, app password, or fingerprint information.
DCENT Tells Users to Update First
DCENT has also issued more detailed instructions for App Wallet users.
The company says users should first update the DCENT app to the latest version before they transfer their assets. It has also told users not to start transactions through the App Wallet before the update.
After the update, users with assets in the App Wallet should move those assets to a secure hardware wallet or another trusted wallet address, based on DCENT’s guidance.
The same advice applies to people who use one recovery phrase across the App Wallet and a hardware wallet.
This order matters because DCENT wants users to update the app before they make any transfer from the affected wallet environment.
A Scam Risk Is Also Growing
A wallet security incident can create a second problem: fake support messages.
When users become worried about lost crypto, scammers can use that fear to pose as wallet staff. They may send a message that claims to offer a refund, recovery service, or emergency transfer.
DCENT has warned users not to trust wallet addresses sent through direct messages or unofficial channels. It has also told users not to click unknown links or follow transfer instructions from unverified sources.
This warning is especially important because blockchain transfers are usually hard to reverse. Sending funds to a scammer’s address can create a second loss on top of the original security problem.
Users should use only DCENT’s official channels for further instructions.
The Attack Method Remains Unknown
One of the biggest unanswered questions is how the abnormal transfers took place.
DCENT has not yet confirmed the attack method. SlowMist also lists the method as unknown in its incident record.
That means it is too early to say whether the event came from a software weakness, a compromised recovery phrase, a malicious transaction process, or another cause.
Some outside researchers have already examined parts of the App Wallet and raised technical concerns, but those observations should not be treated as a confirmed explanation for the incident. The official investigation has not yet established the root cause.
What Users Should Understand
The current picture is fairly clear on one point: the alert centers on the DCENT App Wallet.
People who keep funds in that wallet have been told to update the app and move their assets to a secure hardware wallet or another trusted address.
People who use the same recovery phrase in both an App Wallet and a hardware wallet also need to follow DCENT’s security advice.
At the same time, there is no confirmed evidence that DCENT hardware wallets themselves were compromised. A hardware-only user who never placed the hardware wallet’s recovery phrase into the App Wallet is in a different position from someone who reused the same recovery phrase inside the software wallet.
Investigation Is Still Under Way
The DCENT incident is still developing. The company has said it will provide more information after it confirms the cause, the scope of the impact, and the steps users should take.
For now, the $6.57 million figure is an estimate from security researchers, while the final loss amount remains unconfirmed by DCENT.
The same is true for the full number of affected users. No final public figure has been confirmed.
The key fact is that abnormal transfers have been detected, the App Wallet is the main area of concern, and DCENT has issued an urgent warning to users who may have exposure.
Until the investigation provides more answers, users should rely on official DCENT notices, protect their recovery phrases, avoid unofficial support messages, and take the company’s recommended security steps.