D’CENT Wallet Security Alert: What Users Should Know

D'CENT Wallet and App

D’CENT Wallet Security Alert: Why We Stopped Recommending It

Black Seed Ink Research Lab | September 16, 2026

D’CENT is investigating unauthorized transfers involving its D’CENT App Wallet. In direct communication with Black Seed Ink today, a D’CENT executive told us that more than 2 million XRP had been taken.

For Black Seed Ink readers, this incident is particularly concerning because we withdrew our recommendation of D’CENT in March 2026 - six months before this security event.

Our reason ultimately came down to one issue:

Trust.

D’CENT Requires Too Much Trust

D’CENT has some genuinely attractive features. Biometric approval is convenient. Its app supports a large number of altcoins while making major assets such as Bitcoin, Ethereum, Solana, XRP and XLM easy to view and manage.

We liked those features when we originally reviewed the wallet in September 2025.

But convenience is secondary to security.

The full source code for D’CENT’s hardware-wallet firmware and App Wallet is not publicly available for independent inspection in the same way it is with leading open-source hardware wallets. D’CENT publishes development tools, SDKs and connectors, but that is very different from allowing researchers to independently examine the code responsible for protecting and signing with your private keys.

That means D’CENT users ultimately have to trust D’CENT.

You must trust that the wallet generates your seed securely.

You must trust that private keys cannot be extracted.

You must trust that there are no hidden functions or backdoors.

You must trust every firmware and software update.

And you must trust the manufacturer when it tells you all of those things are true.

We do not believe cryptocurrency owners need to accept that level of trust.

Open source does not make a wallet invulnerable. What it does is allow independent security researchers to examine the code and challenge the manufacturer's claims rather than simply accepting them.

Trezor, OneKey and Keystone 3 Pro all provide substantially greater open-source transparency. OneKey, for example, publishes firmware source for both the Classic 1S and OneKey Pro, including a process for verifying that released firmware corresponds with its published source code. Get 10% off Keystone 3 Pro with code: BlackSeedInk.

Black Seed Ink Research Lab recommends the OneKey Classic 1S and is currently testing the OneKey Pro. So far, we like what we see. More on that wallet after our testing is complete.

Keystone also publishes the Keystone 3 firmware source and provides hashes allowing users and researchers to verify releases.

SafePal deserves a distinction: its X1 is explicitly open source, while the S1/S1 Pro use a different architecture and should not be described as fully open source. Black Seed Ink continues to evaluate wallets based on their complete security model, not a single specification. Get 10% off SafePal S1 Pro with code: BLACKSEED10

Then We Received a D’CENT Wallet With a Broken Seal

The biggest red flag came from D’CENT itself.

Black Seed Ink ordered additional D’CENT wallets directly from the manufacturer for testing.

One arrived with its tamper-evident security seal already broken.

We also found an inconsistent SKU label inside the packaging that did not match what we expected.

This wasn't a wallet purchased through eBay, Amazon or an unknown reseller.

It came directly from D’CENT.

For a product whose sole purpose is protecting private keys and cryptocurrency, we considered that unacceptable.

D'CENT wallet proof of tampered seal

Photo: Black Seed Ink's Research Lab ordered two D’CENT wallets directly from the manufacturer. The wallet on the right arrived with a broken tamper-evident seal and an SKU label that did not match the wallet inside.

On March 19, 2026, we updated our original D’CENT review and withdrew our recommendation.

Today’s Incident Reinforces That Decision

We are not claiming that the broken seal we encountered caused today's security incident. Nor has D’CENT established that its biometric hardware wallet itself has been compromised.

The company currently says the unauthorized transfers involve its App Wallet, and the investigation into the cause remains ongoing.

But today's event reinforces the larger reason we stopped recommending D’CENT:

Self-custody should minimize trust, not replace trust in a bank with complete trust in a wallet manufacturer.

When open-source alternatives exist, we see little reason to accept a closed system protecting something as important as your recovery phrase and private keys.

If You Use the D’CENT App Wallet

If you have assets in the D’CENT App Wallet—or have ever entered the same recovery phrase into both the App Wallet and a hardware wallet - act now.

D’CENT is advising users to update the D’CENT app to the newest version before making any transaction, and then move affected assets to a secure wallet or trusted address.

If moving because your recovery phrase may have been exposed, create a completely new recovery phrase. Moving an old seed into another hardware wallet does not make a potentially compromised seed secure.

Hardware-only D’CENT users who generated their recovery phrase on the hardware device and never entered that phrase into the App Wallet have not, at this time, been identified by D’CENT as affected.

Black Seed Ink Research Lab will continue following the investigation and will update this article as D’CENT releases additional technical information.