KOSUNI CRYPTO
Korea's Crypto Pulse, in English
$BTC $ETH $XRP $SOL $DOGE
News
Neutral

Decent App Wallet Unauthorized Asset Movement Reported; XRP 2.009321 Million Moved in Analysis

Published September 18, 2026 12:18 PM · 1 views $XRP $BTC $ETH $TRX
Decent App Wallet Unauthorized Asset Movement Reported; XRP 2.009321 Million Moved in Analysis

Unauthorized asset movement was reported through Decent app wallet, following the exposure of 347,149 email addresses from Treasure Marketing recipients. Both incidents highlight risks when recovery phrases or external infrastructure are exposed, even if hardware wallets remain uncompromised.

Decent stated that the first report of unauthorized asset movement in its app wallet was received. Potential affected users include those who entered recovery phrases into the app wallet or signed transactions on versions prior to 8.1.0 released November 5, 2025. Affected wallets included Bitcoin (BTC), Ethereum (ETH), XRP, Tron (TRX), and EVM-compatible networks.

Decent emphasized that the key factor is where recovery phrases were entered, not whether hardware and app wallets were connected. While recovery phrases are typically not sent to mobile devices during connection, entering them directly into the app wallet can recreate the same private key in software environments. Exposure of recovery phrases allows attackers to restore wallets without hardware devices.

Decent advised users to update via official app stores, create new wallets with fresh recovery phrases, and transfer assets from old addresses. Users should avoid re-entering old recovery phrases and check coins, tokens, NFTs, staking assets, and token approvals.

Independent on-chain analysis showed 2.009321 million XRP moved across 1,552 XRP Ledger wallets on September 15. XRPL.to noted that blockchain transactions alone cannot confirm how the keys were obtained or directly link to Decent app wallet issues.

Treasure's case involved a security breach at third-party email marketing provider Brevo, which exposed 347,149 email addresses via API. Treasure confirmed its product and wallet systems were not compromised. Brevo cited an SAML-based single sign-on (SSO) processing flaw allowing attackers to access 138 accounts, with contact details stolen from 43 accounts and six used for phishing emails.

Brevo blocked the attack path at 3:30 PM KST on September 10 and reset all active sessions. Attackers sent phishing emails titled 'Critical Security Alert: STM32 Entropy Vulnerability' using Treasure's legitimate email infrastructure, directing recipients to malicious apps that requested wallet backup information.

Treasure blocked the malicious domain within 20 minutes, with approximately 2,500 users accessing the link before mitigation. The company stated assets are safe if users did not enter backup info on phishing pages or apps, advising them to create new wallets with fresh recovery phrases and transfer funds if they did.

Self-custody involves users managing private keys and recovery phrases directly. Wallets function more as tools for transaction signing than storage vaults, making security encompass recovery phrases, linked apps, and user data. Treasure's third-party email provider breach and phishing attempt align with prior industry reports of attackers using trusted-looking alerts to harvest backup information.

Korean Source

This article is an English localization of a Korean-language crypto news report. Original headline: 디센트 앱 지갑 이상 신고…XRP 200만9321개 이동 분석 제시