South Korean hardware wallet D’CENT is investigating unauthorized transfers from some users of its software-based App Wallet, where recovery phrases may have been entered, exposing assets on Bitcoin, Ethereum, XRP Ledger, Tron, and other EVM-compatible networks. Separately, Trezor’s third-party marketing provider Brevo suffered a breach, leading to the export of 347,149 customer email contacts used for phishing attacks. Both companies confirmed their hardware wallet security remained uncompromised, but the incidents highlight how software and third-party vendor vulnerabilities can create routes to compromise recovery phrases.