Crypto hardware wallet makers have a new security problem

Two wallet incidents this week exposed a growing weakness in crypto self-custody: the systems surrounding hardware devices.

D’CENT, a popular hardware wallet in South Korea, said it is investigating unauthorized transfers from some users of its software-based App Wallet, while Trezor, another crypto hardware firm, disclosed that attackers exported 347,149 customer email contacts after breaching third-party marketing provider Brevo.

Neither company has reported a compromise of its hardware-wallet security.

Yet both incidents created routes to the same prize: the recovery phrase that can reconstruct a wallet and control its assets.

D’CENT phrase reuse pulls hardware assets into software risk

D’CENT’s investigation shows how moving a recovery phrase into software can extend risk beyond the device where the wallet was originally created.

The company first received reports of unauthorized transfers on Sept. 16 and found that most affected users were operating its App Wallet, which stores or imports keys on a phone. D’CENT has not confirmed a compromise affecting its hardware products and continues to investigate the cause and total scope of the transfers.

Its current criteria focus on wallets whose recovery phrases were entered into the App Wallet and that had transaction-signing history on versions earlier than 8.1.0, released Nov. 5, 2025. The potential exposure spans Bitcoin, Ethereum, XRP Ledger, Tron, and other EVM-compatible networks.

That creates a potential crossover for hardware users. A recovery phrase generated on a D’CENT device can reconstruct the same private keys elsewhere if the user later imports those words into the software wallet. D’CENT said connecting a hardware device to its app normally does not transfer the recovery phrase onto the phone; manually importing the phrase into App Wallet does.

Read More:  Government to Attempt to Solve Dengue Problem in Three Months: Prime Minister

The company is advising users who meet its criteria to update the app before signing another transaction, create a wallet backed by a new recovery phrase, and transfer affected assets rather than restoring the old phrase onto another device.

D’CENT is also working with exchanges, law enforcement and blockchain investigators to trace and potentially freeze stolen assets.

Trezor breach turns customer data into an attack surface

Trezor’s incident began further from the wallet itself, showing how information about who owns a device can become useful infrastructure for attackers.