NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
NewsLayer PulseLIVEBTC$83,934-0.61%ETH$2,693+0.13%SOL$121.76+3.75%XRP$1.57+2.21%DOGE$0.0975+0.91%ADA$0.255+2.72%Total Cap$2.85T-0.26%Layer Index43 Neutral

Your crypto hardware wallet can stay secure while everything around it fails

Two wallet incidents this week exposed a growing weakness in crypto self-custody: the systems surrounding hardware devices.

CryptoSlate

Publisher

Sep 18, 2026 at 11:50 AM UTC · 4 分钟阅读

Your crypto hardware wallet can stay secure while everything around it fails
Image via CryptoSlate

Key Signal

347,149 Trezor contacts exposed

Last Updated

7 天前

翻译中…

Two wallet incidents this week exposed a growing weakness in crypto self-custody: the systems surrounding hardware devices.

D’CENT, a popular hardware wallet in South Korea, said it is investigating unauthorized transfers from some users of its software-based App Wallet, while Trezor, another crypto hardware firm, disclosed that attackers exported 347,149 customer email contacts after breaching third-party marketing provider Brevo.

Neither company has reported a compromise of its hardware-wallet security.

Yet both incidents created routes to the same prize: the recovery phrase that can reconstruct a wallet and control its assets.

D’CENT phrase reuse pulls hardware assets into software risk

D’CENT’s investigation shows how moving a recovery phrase into software can extend risk beyond the device where the wallet was originally created.

The company first received reports of unauthorized transfers on Sept. 16 and found that most affected users were operating its App Wallet, which stores or imports keys on a phone. D’CENT has not confirmed a compromise affecting its hardware products and continues to investigate the cause and total scope of the transfers.

Its current criteria focus on wallets whose recovery phrases were entered into the App Wallet and that had transaction-signing history on versions earlier than 8.1.0, released Nov. 5, 2025. The potential exposure spans Bitcoin, Ethereum, XRP Ledger, Tron, and other EVM-compatible networks.