SecondFi's Cardano wallet generation software exploited via weak randomness in private key creation, draining ~16M ADA ($2.4M) across 374 addresses in multiple waves.
Security & Exploits ·
SecondFi identified a vulnerability in its native Cardano web wallet generation software stemming from weak randomness in private key creation. The flaw allowed attackers to derive private keys for affected wallets, leading to unauthorized fund transfers across multiple incidents between June 21 and June 24. In total, approximately 16 million ADA (valued at $2.4 million) was stolen from 374 addresses, with the compromise affecting around 198 wallets in an initial wave and thousands more in subsequent attacks.
The company traced the root cause to its proprietary key generation system and stated it had completed an onchain analysis to determine the scope of impact. According to SecondFi's security update, the firm was finalizing an independent technical review with a blockchain security firm to validate its findings. The vulnerability was confined to the web wallet generation software rather than affecting other aspects of the platform.
The exact timeline of fund recovery, whether additional wallets remain at risk, and full details of the independent security review remain unclear. The specific mechanism by which the weak randomness was exploited—and whether similar vulnerabilities might affect other Cardano wallet services—has not been disclosed in available statements.