Tools Crypto Exploit Tracker exploit-0136
Exploit record
Signing flaw in D'CENT's app wallet lets attackers move user funds
- Loss
- $6.6M
- Attack vector
- Software Bug
- Chain
- Multichain
- Sector
- Wallet
What happened
D'CENT's support desk took the first report of an unauthorised asset transfer early on 16 September 2026 in Korea, and the company published an urgent notice that afternoon telling holders to update the app and move assets to a hardware wallet or another address they trust. The exposure sits in the software App Wallet, and D'CENT's hardware devices are sound. SlowMist values the incident at $6.57m.
Two criteria set the scope: an address whose recovery phrase has at some point been entered into the App Wallet, which covers wallets created there, hardware recovery phrases restored into it and App Wallet phrases later moved onto hardware; and a history of signing, which takes in token and NFT transfers, approvals and any transaction made through a connected dApp. Receive-only addresses sit at lower risk. The named chains are Bitcoin, Ethereum, XRPL, TRON and EVM-based chains, and the company points out that USDT on ERC20 or TRC20 rides the same wallet key. Irregular transactions surfaced first on Android, with the same exposure on iOS. D'CENT withholds the technical cause while the investigation runs, to keep it out of the hands of copycats, and has the case with Korean law enforcement while it works with exchanges, foundations and on-chain analysts to freeze and trace funds. The $6.57m figure is SlowMist's valuation, dated 15 September in its hacked database.
Sources
- D'CENT preliminary incident reportstore.dcentwallet.com/blogs/post/app-wallet-incident-report
- D'CENT urgent noticex.com/DCENTWALLETS/status/2100076991798206573
- SlowMist hacked databasehacked.slowmist.io/
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 27 September 2026
