FacebookTwitterLinkedInTelegramCopy LinkEmail
Others

SecondFi Exploit Exposes Wallet Flaw as Recovery Process Begins

SecondFi Exploit Exposes Wallet Flaw as Recovery Process Begins

Cardano ecosystem project SecondFi is beginning the recovery process following one of the network's most significant wallet security incidents, after a flaw in its wallet generation software enabled attackers to compromise user funds.

Summary:

  • Weak wallet key generation enabled attackers to compromise accounts.
  • Around 16 million ADA was stolen during three attack waves.
  • Another 129 million ADA has been secured pending reimbursement.

While approximately 16 million ADA was stolen during the exploit, the team says it secured an additional 129 million ADA before attackers could access the assets, with the funds now held in third-party custody pending an independent audit.

Weak Randomness Caused the Security Breach

Unlike most cryptocurrency exploits that target smart contracts or rely on phishing attacks, the SecondFi incident originated from a vulnerability in the wallet creation process itself.

According to the project, the flaw affected its proprietary web wallet generation software, where insufficient randomness during key generation produced private keys that were more predictable than intended. Security researchers said attackers were able to reproduce or derive private keys associated with affected wallets, allowing them to drain user funds without compromising the Cardano blockchain itself.

Because the vulnerability occurred during wallet creation, experts warn that any wallet generated using the affected software should be considered permanently compromised. Simply importing the same recovery phrase into another Cardano wallet application does not eliminate the underlying security risk, as the compromised private key remains unchanged.

Emergency Response Secures 129 Million ADA

SecondFi and parent company Emurgo said they moved quickly after detecting the attack.

Although attackers successfully stole approximately 16 million ADA, valued at roughly $2.4 million, across three separate attack waves, engineers intercepted additional vulnerable wallets before they could be exploited.

The companies said they transferred approximately 129 million ADA into an isolated secure vault during the incident. Those assets have since been placed under the control of an independent third-party custodian while an external accounting firm verifies ownership records and confirms user balances.


READ MORE: ZachXBT Traces $120 Million USDT Transfers as Tether Freezes Linked Funds


According to the recovery plan, the funds will remain locked until the audit is completed. Only after the reconciliation process concludes will the assets be distributed to verified users.

The independent verification process is intended to ensure reimbursements accurately reflect wallet balances immediately after the exploit was contained.

Users Advised Not to Move Remaining Assets

SecondFi has urged affected users not to move funds or attempt to recover compromised wallets until the reimbursement framework is finalized.

The warning is tied to the recovery process itself. The company said reimbursement calculations rely on a blockchain snapshot captured immediately after the exploit was contained. Moving assets after that point could create discrepancies between on-chain balances and recovery records, potentially delaying or complicating compensation.

Developers also emphasized that migrating a compromised recovery phrase into another Cardano wallet application – including popular alternatives such as Lace or Eternl – does not create a new secure wallet. Because the weakness exists within the original key generation process, the compromised private keys remain vulnerable regardless of which wallet software is used.

Instead, users are expected to wait for official recovery instructions before creating entirely new wallets using secure key generation methods.

Phishing Risks Increase After Major Security Incidents

The exploit has also triggered a wave of phishing attempts targeting affected users.

SecondFi and Emurgo warned that fraudulent accounts on X, Telegram and other social media platforms are impersonating project representatives while promoting fake recovery tools and reimbursement portals.

The companies reiterated that they will never request users’ recovery phrases, private keys or wallet credentials as part of the compensation process. Users have been advised to rely exclusively on official communication channels while the recovery program remains under development.

The incident serves as another reminder that vulnerabilities affecting wallet infrastructure can be as damaging as smart contract exploits, particularly when cryptographic key generation fails to produce sufficiently unpredictable private keys. While the Cardano network itself was not compromised, the attack highlights the importance of secure wallet implementation as institutional and retail adoption of digital assets continues to expand.


The information presented in this article is intended for informational purposes only and should not be interpreted as financial, investment, or trading advice. Coinspress.com does not promote or advocate for any particular investment strategy, asset, or cryptocurrency project. Cryptocurrency markets are highly volatile and unpredictable – always perform your own research and seek guidance from a qualified financial professional before making any investment decisions.

Author
Alexander Stefanov - Editor-in-Chief at Coinspress
Alexander Stefanov

Reporter at CoinsPress

Alex is Editor-in-Chief of Coinspress and co-founder of Millennial Media Group, with nearly a decade of experience covering financial markets - crypto first, then everything else. It started in 2016 with Bitcoin. Like most people at the time, he didn't fully understand it - so he kept digging. Blockchain, tokenomics, the projects, the cycles. That curiosity never stopped, and eventually pulled him into traditional markets too: equities, commodities, macro. Not because he left crypto behind, but because you can't properly understand one without the other. What drives him is straightforward: he wants to know why something is happening, not just that it's happening. Most market coverage stops at the headline - price up, price down, here's a chart. Alex finds that kind of reporting actively unhelpful. If you walk away from an article without understanding the mechanism behind the move, what did you actually learn? He holds a degree in Tourism from New Bulgarian University - not the most obvious path into financial markets, but markets have a way of pulling in people who are simply too curious to stay out. He has authored over 200 in-depth analyses and more than 10,000 articles across crypto and traditional finance. He still thinks every day in markets teaches him something new. That's probably why he hasn't stopped.

Learn more about crypto and blockchain technology.

Glossary