SecondFi Exploit Exposes Wallet Flaw as Recovery Process Begins

Cardano ecosystem project SecondFi is beginning the recovery process following one of the network's most significant wallet security incidents, after a flaw in its wallet generation software enabled attackers to compromise user funds.
Summary:
- Weak wallet key generation enabled attackers to compromise accounts.
- Around 16 million ADA was stolen during three attack waves.
- Another 129 million ADA has been secured pending reimbursement.
While approximately 16 million ADA was stolen during the exploit, the team says it secured an additional 129 million ADA before attackers could access the assets, with the funds now held in third-party custody pending an independent audit.
Weak Randomness Caused the Security Breach
Unlike most cryptocurrency exploits that target smart contracts or rely on phishing attacks, the SecondFi incident originated from a vulnerability in the wallet creation process itself.
According to the project, the flaw affected its proprietary web wallet generation software, where insufficient randomness during key generation produced private keys that were more predictable than intended. Security researchers said attackers were able to reproduce or derive private keys associated with affected wallets, allowing them to drain user funds without compromising the Cardano blockchain itself.
Because the vulnerability occurred during wallet creation, experts warn that any wallet generated using the affected software should be considered permanently compromised. Simply importing the same recovery phrase into another Cardano wallet application does not eliminate the underlying security risk, as the compromised private key remains unchanged.
Emergency Response Secures 129 Million ADA
SecondFi and parent company Emurgo said they moved quickly after detecting the attack.
Although attackers successfully stole approximately 16 million ADA, valued at roughly $2.4 million, across three separate attack waves, engineers intercepted additional vulnerable wallets before they could be exploited.
The companies said they transferred approximately 129 million ADA into an isolated secure vault during the incident. Those assets have since been placed under the control of an independent third-party custodian while an external accounting firm verifies ownership records and confirms user balances.
READ MORE: ZachXBT Traces $120 Million USDT Transfers as Tether Freezes Linked Funds
According to the recovery plan, the funds will remain locked until the audit is completed. Only after the reconciliation process concludes will the assets be distributed to verified users.
The independent verification process is intended to ensure reimbursements accurately reflect wallet balances immediately after the exploit was contained.
Users Advised Not to Move Remaining Assets
SecondFi has urged affected users not to move funds or attempt to recover compromised wallets until the reimbursement framework is finalized.
The warning is tied to the recovery process itself. The company said reimbursement calculations rely on a blockchain snapshot captured immediately after the exploit was contained. Moving assets after that point could create discrepancies between on-chain balances and recovery records, potentially delaying or complicating compensation.
Developers also emphasized that migrating a compromised recovery phrase into another Cardano wallet application – including popular alternatives such as Lace or Eternl – does not create a new secure wallet. Because the weakness exists within the original key generation process, the compromised private keys remain vulnerable regardless of which wallet software is used.
Instead, users are expected to wait for official recovery instructions before creating entirely new wallets using secure key generation methods.
Phishing Risks Increase After Major Security Incidents
The exploit has also triggered a wave of phishing attempts targeting affected users.
SecondFi and Emurgo warned that fraudulent accounts on X, Telegram and other social media platforms are impersonating project representatives while promoting fake recovery tools and reimbursement portals.
The companies reiterated that they will never request users’ recovery phrases, private keys or wallet credentials as part of the compensation process. Users have been advised to rely exclusively on official communication channels while the recovery program remains under development.
The incident serves as another reminder that vulnerabilities affecting wallet infrastructure can be as damaging as smart contract exploits, particularly when cryptographic key generation fails to produce sufficiently unpredictable private keys. While the Cardano network itself was not compromised, the attack highlights the importance of secure wallet implementation as institutional and retail adoption of digital assets continues to expand.
The information presented in this article is intended for informational purposes only and should not be interpreted as financial, investment, or trading advice. Coinspress.com does not promote or advocate for any particular investment strategy, asset, or cryptocurrency project. Cryptocurrency markets are highly volatile and unpredictable – always perform your own research and seek guidance from a qualified financial professional before making any investment decisions.











