D'CENT Biometric
IoTrust Co., Ltd.
Data verified on unchanged since the sources
Worth it if you want a hardware wallet with on-device biometric fingerprint unlock, a CC EAL5+ secure element and very broad support for 85+ blockchains with readable signing.
Avoid it if you require an air-gapped device or open-source firmware: it uses Bluetooth and USB, the firmware is closed, and it was sold out at last check.
The D'CENT Biometric is the hardware wallet from South Korea's IoTrust that builds a fingerprint sensor into the device itself: you confirm a transaction with your finger, without typing a PIN on screen. Keys stay in a secure element certified to CC EAL5+ with a proprietary SecureOS. It connects to the phone over encrypted Bluetooth (and to a computer via USB): the wireless link means the device is NOT air-gapped. It is very broad on multi-asset, with over 85 blockchains and thousands of supported tokens, and includes "Trusted Clear Signing" technology. The list price is USD 119 (~€110), often discounted. At the time of verification the official store listed it as sold out. Firmware is not open-source.
Data & conditions
| Fund custody | Self-custody (funds in your control) |
|---|---|
| Type | Hardware (cold storage) |
| Source code | Closed-source |
| Recovery | Seed phrase 12/24 parole (BIP-39) |
| Bitcoin-only | No |
| Supported chains | Bitcoin, Ethereum, ERC-20, XRP, Solana |
| Price | €110 |
| Secure element | Yes |
| Air-gapped | No |
| Connectivity | Bluetooth |
| Built-in swap | Yes |
| Built-in staking | Yes |
| Segment | B2C |
| MiCA / License status | Nessuna (hardware wallet self-custody) |
Plans & pricing
Strengths
- On-device biometric fingerprint unlock; CC EAL5+ secure element with SecureOS; very broad multi-asset support (85+ blockchains); Trusted Clear Signing for human-readable signing.
- Self-custody: funds stay in your wallet — the platform cannot touch them.
- No KYC: usable without identity verification.
Weaknesses
- Not air-gapped: uses Bluetooth (and USB), not QR or microSD; closed-source firmware that cannot be verified; listed as sold out on the official store at the time of verification.
- Closed source: no way to verify what it does with wallet and data.
Verdict
Score 3.8/5, solid profile. In its favour: on-device biometric fingerprint unlock; CC EAL5+ secure element with SecureOS; very broad multi-asset support (85+ blockchains); Trusted Clear Signing for human-readable signing. The trade-off to weigh: not air-gapped: uses Bluetooth (and USB), not QR or microSD; closed-source firmware that cannot be verified; listed as sold out on the official store at the time of verification.
On the Sovereignty lens the score is 3.5/5 (solid): the strength is fund control (5.0/5), while trustless / auditability (0.0/5) is the weak link.
Promp's editorial rating based on real fees and net annual cost. Promp reviews third-party products independently.
"Sovereignty" rating: score computed on privacy/anonymity (30%), fund control (20%), censorship resistance (20%), trustless/auditability (20%) and costs (10%). Same data, different weights.
Reputation
What happened to people who used D'CENT Biometric, and what users say. External signals: they do not feed the promp.it rating.
Incidents & regulatory actions
Notable incidentsDocumented events with consequences still open. Each entry carries a source and a date.
-
Hack / funds theft Critical ● open
Unauthorized transfers from the App Wallet: keys compromised, funds still at risk
On 16 Sep 2026 IoTrust (D'CENT) disclosed that it had detected unauthorized asset transfers from the D'CENT App Wallet, the in-app software wallet, and urged users to move their funds immediately. The official 17 Sep report lists the exposure criteria: a recovery phrase entered or restored into the App Wallet, an address with signing history (sends, token approvals, dApp transactions), and signing performed on an app version below 8.1.0 (released 5 Nov 2025), across Bitcoin, Ethereum, XRPL, TRON, EVM networks and others. The first unauthorized transactions were observed on Android, but D'CENT states the same exposure applies to iOS. The company has NOT published the technical root cause ("it could be used in identical or similar attacks") nor a total loss figure. Third-party on-chain analyses, unconfirmed by the company, size the XRPL leg alone: an automated sweep of 1,552 accounts for 2,009,321 XRP between 16:29 and 18:34 UTC on 15 Sep, and a later estimate by the XRPL intel account of roughly 6,160 addresses involved for about 9.3 million XRP in total, of which 2 million are still in monitored wallets and 7 million have been moved to unknown destinations (reported on 20 Sep by a single outlet, unconfirmed by the company and not consistent with the 2,009,321 XRP reconstructed on-chain: read it as an estimate, not as the total damage; and it is denominated in XRP, not dollars). Korean law enforcement has taken on the case; D'CENT is tracing funds with an external security firm and asking exchanges and projects to freeze them. ⚠️ Hardware wallets connected to the app are NOT affected — the key never leaves the device — BUT if a hardware wallet's recovery phrase was ever entered or restored into the App Wallet, the same risk applies. As of 21 Sep the company is still publicly asking people to spread the warning to "prevent further damage": exposed keys stay compromised until the funds are moved. Update of 24 Sep: a later reconstruction by the analytics platform XRPL.to, picked up by the trade press, puts the XRPL leg alone at roughly 11.75 million XRP taken from 6,678 accounts across six separate waves between 15 and 20 September — around 18.7 million dollars at the rate used by the source (1.59 $ per XRP). It is the broadest estimate so far and supersedes the earlier ones, but it remains a third-party reconstruction: the company has not confirmed it, has published no total of its own, and has announced no reimbursement. No substantive update has followed the official 17 Sep report: IoTrust's last public move remains the 21 Sep appeal to check and move funds, and the technical root cause is still undisclosed by the company's stated choice. The traced waves stop on 20 September, but the exposed keys remain compromised: anyone who has not yet rotated their recovery phrase can be swept at any moment, which is why this incident is still flagged as active.
↗ source
verified on
FAQ
How much does the D'CENT Biometric cost?
The list price is USD 119, about €110 at the August 2026 exchange rate, often on sale (down to USD 119 from USD 159 on the official store). At the time of verification the model was sold out.
How does the biometric unlock work?
The fingerprint sensor is built into the device: you register up to two fingerprints and confirm a transaction with a finger tap, with a PIN (4-8 digits) as backup. Keys stay in the CC EAL5+ secure element and never leave the device.
Is the D'CENT Biometric air-gapped?
No. It connects to the phone over encrypted Bluetooth and to a computer via USB. Keys stay protected in the secure element, but the wireless connectivity rules out a fully offline mode.
Sources
- store.dcentwallet.com Prezzo usd · Secure element · Biometrico · Connettivita · +3 Data verified on Aug 3, 2026