Cardano wallet exploit: SecondFi traces attack to private key flaw, warns users not to restore seed phrases

ambcryptoОпубліковано о 2026-06-25Востаннє оновлено о 2026-06-25

Анотація

SecondFi has identified the root cause of the recent Cardano wallet exploit, which drained approximately 16 million ADA ($2.4 million) from 374 wallets. The attack stemmed from a deterministic nonce derivation flaw in its software signer, allowing attackers to mathematically reconstruct private keys from public blockchain data after transactions were signed. The company warns affected users not to restore their compromised recovery phrases into another wallet, as the vulnerability exists at the private key level, meaning addresses remain exposed. Users are advised against moving funds or withdrawing staking rewards and should instead await SecondFi's official recovery process. Emergency containment has secured around 129 million ADA pending recovery. SecondFi has launched a restoration fund, engaged external security auditors, and identified two attacker groups responsible for the automated draining campaigns between June 21 and 23. The platform remains in maintenance mode during ongoing security reviews.

SecondFi has identified the root cause of the recent exploit that targeted hundreds of Cardano wallets. It warned affected users not to restore their recovery phrases into another wallet, as the compromise occurs at the private key level rather than the wallet application itself.

In an investigation update published on June 25, the Cardano wallet provider said the attack stemmed from a deterministic nonce derivation flaw in its software signer. This allowed attackers to mathematically reconstruct private keys from publicly available blockchain data after affected addresses signed transactions.

The findings come days after the exploit drained approximately 16 million ADA, worth about $2.4 million. It affected 374 wallets across four separate wallet-draining events.

SecondFi says signing flaw exposed private keys

According to SecondFi, the vulnerability existed at the address level. This means compromised keys remain exposed even if users import the same recovery phrase into another Cardano wallet.

The company said every transaction signed by an affected address leaked sufficient information for attackers to derive that address’s private key from on-chain data.

As a result, SecondFi urged affected users not to migrate their recovery phrases to another wallet or attempt to move funds independently. It warned that compromised addresses could be drained again.

It also cautioned against withdrawing staking rewards, as such transactions could expose funds to attackers monitoring the mempool.

Instead, the wallet provider advised affected users to wait for its official recovery process while submitting claims through its support portal.

Recovery effort enters next phase

SecondFi said it has completed mapping all wallets affected during the initial exploit and has begun the next stage of its recovery program.

The company confirmed that 374 wallet addresses were impacted, with approximately 16 million ADA compromised. It added that emergency containment efforts have already secured around 129 million ADA, which is being held pending recovery operations.

SecondFi has also established a dedicated restoration fund to reimburse affected users and engaged multiple external security firms to audit its systems before resuming normal operations.

The platform remains in maintenance mode while independent security reviews continue.

Investigators identify two attacker groups

As part of its latest update, SecondFi said it had identified and isolated the blockchain addresses associated with two attackers responsible for the automated wallet-draining campaigns between June 21 and 23.

According to the investigation, one attacker drained 171 wallets across two waves. At the same time, a second actor compromised 203 wallets during a separate sweep.

The company also disclosed that approximately 4.02 million ADA linked to the exploit remains in one identified collection wallet. The wallet has been flagged and remains under active monitoring.


Final Summary

  • SecondFi traced the Cardano wallet exploit to a deterministic nonce-derivation flaw that enabled attackers to reconstruct private keys from public blockchain data.
  • The company has launched a recovery program, identified two attacker groups, and warned affected users not to restore compromised recovery phrases into other wallets.

Трендові криптовалюти

Пов'язані питання

QWhat was the root cause of the Cardano wallet exploit identified by SecondFi?

AThe root cause was a deterministic nonce derivation flaw in its software signer, which allowed attackers to mathematically reconstruct private keys from publicly available blockchain data after affected addresses signed transactions.

QWhy did SecondFi warn affected users not to restore their recovery phrases into another wallet?

ABecause the compromise occurs at the private key level, not the wallet application. This means the compromised keys remain exposed even if the recovery phrase is imported into a different Cardano wallet, and any funds moved to a new address from the same seed could be drained again.

QHow many wallets and what total amount of ADA were affected by the exploit according to the article?

AApproximately 374 wallet addresses were affected, with about 16 million ADA (worth around $2.4 million) compromised.

QWhat were the two main actions SecondFi advised affected users to take or avoid?

ASecondFi advised affected users to: 1) Wait for its official recovery process and submit claims through its support portal, and 2) Avoid migrating recovery phrases to another wallet, moving funds independently, or withdrawing staking rewards, as these actions could expose funds to attackers.

QWhat did SecondFi's investigation reveal about the attackers involved in the exploit?

AThe investigation identified two attacker groups. One drained 171 wallets across two waves, and a second actor compromised 203 wallets during a separate sweep. Approximately 4.02 million ADA linked to the exploit remains in one identified collection wallet.

Пов'язані матеріали

Tokenized SpaceX Stock Liquidations Show Crypto Leverage Reaching Private Markets

Tokenized SpaceX stock positions recently experienced significant liquidations, illustrating the growing risk as crypto-style leverage enters private-market equity products. This episode highlights a key tension in the tokenized asset narrative: while these products aim to democratize access to high-demand, late-stage private companies like SpaceX, pairing them with leverage transforms them into high-volatility instruments more akin to crypto derivatives than traditional equity investments. The demand for tokenized SpaceX exposure stems from its brand power, scarcity, and investor interest. However, this access does not eliminate inherent risks, including jurisdictional limits, complex redemption terms, liquidity constraints, and differences in investor rights compared to direct ownership. The incident serves as a broader warning for the tokenized real-world asset (RWA) market. For sustainable growth, platforms must establish clear rules around custody, pricing, leverage, and disclosures. Regulators are likely to scrutinize whether such products are marketed as equity access while functioning as leveraged derivatives. This story underscores ongoing market themes: increasing regulatory specificity, the integration of crypto products with traditional finance rails, and heightened sensitivity to liquidity conditions. It reinforces the need to view developments through the lens of evolving market structure, leverage, and institutional participation rather than as isolated price catalysts.

bitcoinist1 год тому

Tokenized SpaceX Stock Liquidations Show Crypto Leverage Reaching Private Markets

bitcoinist1 год тому

Торгівля

Спот
Ф'ючерси

Популярні статті

Як купити ADA

Ласкаво просимо до HTX.com! Ми зробили покупку Cardano (ADA) простою та зручною. Дотримуйтесь нашої покрокової інструкції, щоб розпочати свою криптовалютну подорож.Крок 1: Створіть обліковий запис на HTXВикористовуйте свою електронну пошту або номер телефону, щоб зареєструвати обліковий запис на HTX безплатно. Пройдіть безпроблемну реєстрацію й отримайте доступ до всіх функцій.ЗареєструватисьКрок 2: Перейдіть до розділу Купити крипту і виберіть спосіб оплатиКредитна/дебетова картка: використовуйте вашу картку Visa або Mastercard, щоб миттєво купити Cardano (ADA).Баланс: використовуйте кошти з балансу вашого рахунку HTX для безперешкодної торгівлі.Треті особи: ми додали популярні способи оплати, такі як Google Pay та Apple Pay, щоб підвищити зручність.P2P: Торгуйте безпосередньо з іншими користувачами на HTX.Позабіржова торгівля (OTC): ми пропонуємо індивідуальні послуги та конкурентні обмінні курси для трейдерів.Крок 3: Зберігайте свої Cardano (ADA)Після придбання Cardano (ADA) збережіть його у своєму обліковому записі на HTX. Крім того, ви можете відправити його в інше місце за допомогою блокчейн-переказу або використовувати його для торгівлі іншими криптовалютами.Крок 4: Торгівля Cardano (ADA)Легко торгуйте Cardano (ADA) на спотовому ринку HTX. Просто увійдіть до свого облікового запису, виберіть торгову пару, укладайте угоди та спостерігайте за ними в режимі реального часу. Ми пропонуємо зручний досвід як для початківців, так і для досвідчених трейдерів.

1.0k переглядів усьогоОпубліковано 2024.12.10Оновлено 2026.06.02

Як купити ADA

Обговорення

Ласкаво просимо до спільноти HTX. Тут ви можете бути в курсі останніх подій розвитку платформи та отримати доступ до професійної ринкової інформації. Нижче представлені думки користувачів щодо ціни ADA (ADA).

活动图片