More info here as this situation is still actively developing: X: DCENT_Official
That’s not their real account, the real one is already in the original post.
Dcent isn’t the most well known brand for hardware wallets and I wasn’t even aware that they also had a mobile app that allows you to create a hot wallet. That seems counterintuitive for that kind of brand. Now they will be associated with having poor security, even if hardware wallets weren’t affected.
It could be another poor entropy issue, but we will have to wait until there is more information to know the exact cause.
Good catch! Thanks for pointing it out! Regarding the incident itself, it's not yet known what caused it, but "weak entropy" doesn't seem to make sense to me, since that would have caused the wallet to be drained upon creation, not subjected to days of "abnormal transfers", as described. It's more likely to be a session key compromise, a hacked API, a transaction signing bug, or a trojanized app update, but it'll have to wait for a statement from "DCENT" to know for sure.
Also, that's another place where they screwed up because they're primarily a hardware wallet maker while also running a software hot wallet, so having the same name invites unnecessary confusion when a security issue like this arises. People will be trying to figure out which of their products is affected, which could lead to unnecessary rumors.