DCENT Wallet has urged users of its software-based app wallet to move their assets after detecting abnormal asset transfers, while Core Lightning issued a separate warning over a potential issue involving experimental features that may put user funds at risk.
South Korea-based IoTrust, which develops DCENT, said it has launched an emergency investigation into the wallet activity. Users holding assets in the DCENT app wallet were told to transfer them to a secure hardware wallet or another trusted address as soon as possible, regardless of the amount held.
DCENT Warning Centers on Software Wallets
Initial findings place the abnormal transfers within the DCENT app wallet. The company’s biometric and card-type products use separate hardware-based key storage, but users who imported the same recovery phrase from a hardware wallet into the software wallet fall within the precautionary warning.
A recovery phrase imported into the app can recreate the same underlying wallet addresses and private keys. DCENT specifically instructed users sharing the same mnemonic between the app wallet and a hardware wallet to move the associated assets.
The company has not published a loss estimate, affected-user count or technical cause. Its investigation is examining the source of the abnormal transfers, the scope of affected wallets and the response required for users.
DCENT supports a software wallet alongside its biometric and card-based hardware products, with the app also allowing users to import wallets through 12- or 24-word recovery phrases.
Core Lightning Flags Experimental Features
Core Lightning separately warned node operators that it is investigating a potential issue affecting experimental features that may impact user funds.
Operators running experimental features were told to disable them immediately while developers investigate. Core Lightning’s documentation classifies these options as features intended for advanced testing and explicitly warns that they are subject to breakage between releases.
The project has not disclosed which experimental component is responsible or published a confirmed loss amount. Start9 advised operators using its infrastructure to disable dual funding and liquidity ads while the investigation continues.
The alert comes weeks after Core Lightning operators were told to take affected nodes offline during a separate round of security work involving vulnerabilities reported to the project.
Investigations Remain Active
DCENT said further instructions will follow once it establishes the cause and affected scope of the abnormal transfers. Until then, its current guidance is to move assets controlled through the app wallet, including wallets whose recovery phrases were also imported from hardware devices.
Core Lightning’s current instruction is narrower: operators using experimental functionality should disable those features while its investigation continues. The project has not yet published a technical advisory identifying the affected feature or failure mechanism.



Be the first to comment