Cardano钱包遭遇SecondFi漏洞攻击,私钥缺陷引发安全警告

bitcoinistPubblicato 2026-06-27Pubblicato ultima volta 2026-06-27

Introduzione

Cardano生态钱包服务商SecondFi(前身为Yoroi钱包关联品牌)因其专有的网页版钱包生成软件存在关键漏洞,已暂停服务。该漏洞导致用户私钥暴露,并引发了大规模的ADA代币盗窃事件。 初步报告显示,约有374个钱包被盗走约1600万ADA(当时价值约240万美元)。而安全公司SlowMist警告,总损失可能超过1.29亿ADA(价值超2000万美元)。核心问题是SecondFi的私钥生成过程存在缺陷,这使得攻击者能够直接访问相关钱包。 需要明确的是,此次事件是SecondFi钱包软件层面的安全漏洞,并非Cardano区块链协议本身被黑客攻击。这对市场和用户的理解至关重要。 安全人员向受影响用户发出强烈警告:切勿将已泄露的助记词(种子短语)导入其他钱包,因为这只会将已暴露的私钥转移到新界面,无法解决问题。同时,用户应警惕虚假的恢复链接或第三方退款平台,谨防二次诈骗,并仅依赖官方渠道的信息。 此次事件提醒Cardano社区,区块链安全不仅在于底层协议,钱包生成、浏览器界面、助记词处理等环节同样可能成为关键风险点。目前,事件仍在发展中,最终影响范围和后续处理方案有待官方进一步确认。

SecondFi,曾与Yoroi钱包品牌有关联,在据称其专有的基于网络的钱包生成软件中存在严重缺陷、导致私钥泄露并造成重大ADA盗窃事件后,已暂停服务。此事件已引发对受影响用户的紧急警告,但验证后的信息源在一个关键点上表述明确:这并非Cardano区块链协议本身遭受黑客攻击。

内容提要

  • SecondFi在据称其私钥生成缺陷导致ADA钱包受损后暂停服务。
  • 初步报告称损失约1600万ADA,涉及374个钱包,价值约240万美元。
  • 安全公司慢雾(SlowMist)警告,总影响可能超过1.29亿ADA,即价值超过2000万美元的资产。
  • 问题仅限于SecondFi的钱包生成软件,而非Cardano协议。
  • 已警告受影响用户不要将受损的助记词(种子短语)恢复到其他钱包。

私钥生成是事件核心

经核实的报道将此次漏洞描述为与SecondFi专有的基于网络的钱包软件中私钥生成相关的缺陷。这一区分至关重要。如果私钥生成不安全或遭到泄露,即使底层区块链运行正常,攻击者也可能访问钱包。

初步估计有1600万ADA从374个钱包中被盗,按相关估值计算约合240万美元。安全公司慢雾随后警告,更广泛的影响可能超过1.29亿ADA,即超过2000万美元的资产。这些数字应谨慎对待,但它们说明了为何此事件迅速成为Cardano生态系统中的一个高优先级安全事件。

Cardano协议未受影响

此事件中最重要的一条界线是哪些事情并未发生。核实的报道中并未描述Cardano网络本身遭到黑客攻击或破坏。问题仅限于SecondFi使用的钱包生成软件,这意味着风险集中在受影响的钱包和私钥,而非Cardano底层的共识机制或账本安全。

这种区分对用户和市场解读至关重要。钱包泄露仍然可能很严重,尤其是涉及私钥时,但它与协议级别的漏洞利用有着根本区别。错误陈述这条界线可能造成不必要的恐慌,并损害公众对此事件的理解。

对受影响用户的警告

最强烈的安全警告也是最简单的:受影响用户不应将受损的助记词恢复到其他钱包。如果私钥本身是在不安全的情况下生成或已暴露,那么将相同的恢复短语导入其他地方并不能解决问题。这只会将相同的受损凭证移到一个新的界面中。

核实的信息包还警告要提防未经核实的恢复链接或第三方退款平台。这是加密货币遭攻击后常见的模式:诈骗者通常会迅速出现,冒充客服台、恢复团队或退款门户。用户应仅依赖SecondFi的官方更新和公认的安全公告。

接下来会发生什么

下一阶段将取决于SecondFi是否会发布完整的事后分析报告,安全公司是否能确认受影响钱包的最终范围,以及是否会通过官方渠道建立任何恢复或补偿流程。在此之前,最安全的界定是:这是一个持续的钱包安全事件,损失估计可能还会上升。

对于Cardano社区而言,这一事件提醒我们,区块链安全并不止于协议层。钱包生成、基于浏览器的界面、助记词处理和用户恢复流程都可能成为关键故障点。在此次事件中,最紧迫的任务是在确认最终影响范围的同时,帮助受影响用户避免进一步暴露风险。

本报告基于来自Blockonomi Exploit和Crypto Economy Warning的信息。

本文由新闻部撰写,Samuel Rae编辑。

报告来源:Blockonomi Exploit 网站

Crypto di tendenza

Domande pertinenti

Q根据文章,SecondFi(前身为Yoroi钱包品牌)暂停服务的主要原因是什么?

A主要原因是其专有的基于网络的钱包生成软件存在关键漏洞,该漏洞暴露了用户的私钥,并导致了ADA(Cardano的原生代币)的重大失窃事件。

Q这次安全事件直接攻击或破坏了Cardano区块链协议本身吗?

A没有。文章明确指出,这次事件并非对Cardano区块链协议本身的攻击或破坏。问题仅限于SecondFi使用的钱包生成软件,风险集中在受影响的钱包和私钥上,与Cardano的基础层共识或账本安全性无关。

Q文章提到的关于受影响用户最重要的安全警告是什么?

A最重要的安全警告是:受影响的用户绝对不应该将已泄露的助记词(种子短语)恢复到任何其他钱包中。如果私钥本身是不安全生成或已暴露的,那么将相同的恢复短语导入新钱包不仅无法解决问题,反而可能将已泄露的凭证转移到新的界面上,造成进一步损失。

Q安全公司SlowMist对这次事件可能造成的损失规模提出了什么警告?

ASlowMist警告称,此次事件的总体影响可能超过1.29亿枚ADA,按文中的参考估值计算,资产价值超过2000万美元。这远高于最初估计的约374个钱包、1600万枚ADA(约合240万美元)的损失。

Q文章指出,对于Cardano社区来说,这次事件起到了什么提醒作用?

A这次事件提醒Cardano社区,区块链安全并不仅仅停留在协议层面。钱包生成、基于浏览器的界面、助记词处理以及用户恢复流程等环节,都可能成为关键的单点故障。安全需要贯穿整个生态系统的各个环节。

Letture associate

In the AI Era, What's Left for Bitcoin?

As Bitcoin falls below $60,000, the author reflects on the relationship between AI and Bitcoin, seeing them as two sides of the same coin. In the AI era, the cost of generating content has plummeted, making fake text, images, and videos increasingly easy and cheap to produce. This has led to a fundamental shift: while AI dramatically lowers the cost of information production, it also undermines trust and authenticity online. What becomes truly valuable is not more content, but the ability to verify what is real—"verifiability." This perspective offers a new lens for Bitcoin. Its massive energy consumption, often criticized as wasteful, is reinterpreted. While AI burns energy to enhance "capability" and efficiency, Bitcoin burns energy to produce "verifiability." Its purpose is not to be trusted but to enable a system where no trust in intermediaries—banks, platforms, or developers—is needed. Every transaction and the entire ledger's history is secured by cryptography and a decentralized network of nodes, making it independently verifiable. AI cannot forge a transaction on the Bitcoin network because the system is designed for proof, not generation. The author draws a historical parallel to the Renaissance: the printing press drastically reduced the cost of copying knowledge, while double-entry bookkeeping reduced the cost of trust in commerce. Today, AI is the new printing press, reducing content creation costs to near zero. Blockchain, and Bitcoin as its pioneer, may be the modern equivalent of double-entry bookkeeping—a foundational technology for verifying digital asset ownership and historical records without centralized authorities. Thus, AI and blockchain are not competitors. AI lowers the cost of creation; blockchain lowers the cost of verification. In an age where AI can generate anything, true scarcity may lie not in more content, but in independently verifiable facts. Whether the market will reprice Bitcoin accordingly remains uncertain, but its core value proposition as a "machine for producing verifiability" becomes strikingly relevant.

marsbit1 h fa

In the AI Era, What's Left for Bitcoin?

marsbit1 h fa

In the Age of AI, What's Left for Bitcoin?

Author: Sevclub, Seven Research Amid Bitcoin's recent drop below $60k, the author reflects on a growing sense that AI and Bitcoin are two sides of the same coin. Today, encountering any content triggers a new default question: "Was this made by AI?" The cost of generating convincing text, images, and video is now negligible. While the internet lowered information *distribution* costs, AI is crashing information *production* costs to near zero. The consequence is a flood of content where truth and falsehood are increasingly indistinguishable. In this environment, what becomes truly valuable is not more information, but the ability to verify what is real—"verifiability." This reframes the common criticism that Bitcoin "wastes electricity." AI consumes power to produce "capability" (e.g., more powerful models). Bitcoin consumes power to produce something else: "verifiability." Bitcoin's core purpose isn't about belief or trust in any institution, developer, or even its creator. It's about enabling independent verification. Every bitcoin's origin, every transaction, and the integrity of the entire ledger are secured by mathematics, cryptography, and a global network of nodes. AI can fabricate convincing media, but it cannot falsify a transaction on the Bitcoin network. The expended energy makes篡改历史 (tampering with history) prohibitively expensive, purchasing a globally verifiable ledger. The author draws a historical parallel to the Renaissance. The printing press drastically reduced the cost of copying knowledge, while double-entry bookkeeping reduced the cost of trust in commerce—one enabled creation, the other verification. Today, AI is the new printing press, driving content production costs toward zero. The question becomes: what is this era's "double-entry bookkeeping"? Blockchain appears to be the leading candidate. It doesn't verify which news is true or which image is real, but it provides a foundational layer for independently verifying asset ownership and historical records in the digital realm without centralized authorities. Therefore, AI and blockchain are not in competition. AI lowers the cost of *generation*. Blockchain (and Bitcoin as a prime example) lowers the cost of *verification*. One creates, the other proves. Whether Bitcoin ultimately succeeds remains uncertain, facing potential challenges from quantum computing, regulation, and technical evolution. However, the author now sees it less as a "machine for making bitcoin" and more as a "machine for making verifiability." In an age where AI can generate anything, true scarcity may no longer be "more content," but "more independently verifiable facts." Whether the market will price this accordingly is a separate question.

链捕手1 h fa

In the Age of AI, What's Left for Bitcoin?

链捕手1 h fa

Trading

Spot

Articoli Popolari

Come comprare ADA

Benvenuto in HTX.com! Abbiamo reso l'acquisto di Cardano (ADA) semplice e conveniente. Segui la nostra guida passo passo per intraprendere il tuo viaggio nel mondo delle criptovalute.Step 1: Crea il tuo Account HTXUsa la tua email o numero di telefono per registrarti il tuo account gratuito su HTX. Vivi un'esperienza facile e sblocca tutte le funzionalità,Crea il mio accountStep 2: Vai in Acquista crypto e seleziona il tuo metodo di pagamentoCarta di credito/debito: utilizza la tua Visa o Mastercard per acquistare immediatamente CardanoADA.Bilancio: Usa i fondi dal bilancio del tuo account HTX per fare trading senza problemi.Terze parti: abbiamo aggiunto metodi di pagamento molto utilizzati come Google Pay e Apple Pay per maggiore comodità.P2P: Fai trading direttamente con altri utenti HTX.Over-the-Counter (OTC): Offriamo servizi su misura e tassi di cambio competitivi per i trader.Step 3: Conserva Cardano (ADA)Dopo aver acquistato Cardano (ADA), conserva nel tuo account HTX. In alternativa, puoi inviare tramite trasferimento blockchain o scambiare per altre criptovalute.Step 4: Scambia Cardano (ADA)Scambia facilmente Cardano (ADA) nel mercato spot di HTX. Accedi al tuo account, seleziona la tua coppia di trading, esegui le tue operazioni e monitora in tempo reale. Offriamo un'esperienza user-friendly sia per chi ha appena iniziato che per i trader più esperti.

1.3k Totale visualizzazioniPubblicato il 2024.12.10Aggiornato il 2026.06.02

Come comprare ADA

Discussioni

Benvenuto nella Community HTX. Qui puoi rimanere informato sugli ultimi sviluppi della piattaforma e accedere ad approfondimenti esperti sul mercato. Le opinioni degli utenti sul prezzo di ADA ADA sono presentate come di seguito.

活动图片