Cardano wallet provider SecondFi to shut down after $2.4M ADA theft
Security & Exploits ·
A transaction-signing flaw exposed users' private keys, letting hackers drain funds before the company said it would close its doors.
SecondFi, a wallet provider built for the Cardano ecosystem, will shut down after hackers stole $2.4M worth of ADA by exploiting a flaw in how the wallet handled transaction signing, according to Coindesk. The bug reportedly exposed users' private keys, giving attackers a direct path to the funds held in affected wallets.
The exact mechanism of the exploit tied to the signing process, which is meant to authorize transactions without revealing sensitive key material. Instead, the flaw allowed private keys to be exposed during that process, undermining the core security assumption users rely on when a wallet signs transactions on their behalf. Once keys were compromised, attackers were able to move ADA out of affected addresses.
The incident has already rippled beyond SecondFi itself. Midnight, a project connected to the Cardano ecosystem, temporarily suspended redemptions for its Glacier Drop program in response to the security incident linked to SecondFi's wallet. Separately, SecondFi has told users that funds could be recovered within two weeks, as EMURGO works to finalize a restoration plan covering 374 affected addresses.
The breach lands at a moment when Cardano's broader ecosystem is drawing renewed attention for other reasons, including a rise in wallets holding more than 1 million ADA, which recently reached 67.47% of total supply, their highest share since 2020. It also follows separate strain elsewhere in Cardano-adjacent infrastructure, with the analytics platform TapTools beginning a wind-down after five executive departures left it short on technical expertise.
What remains unresolved is how the transaction-signing flaw originated, whether it was specific to SecondFi's implementation or reflects a broader weakness in wallet software used across the Cardano ecosystem, and how many of the 374 affected addresses will ultimately be made whole. The timeline for EMURGO's restoration plan, described as within two weeks, has not yet been confirmed as complete, and no detail has been provided on whether the stolen $2.4M in ADA has been traced, frozen, or recovered from the attackers. It is also unclear whether SecondFi's shutdown is final or contingent on the outcome of the recovery effort.