SecondFi suffers exploit through compromised Cardano web wallet generation software; 129M ADA linked to suspected hacker wallets, losses may exceed $20M.
Security & Exploits ·
SecondFi disclosed that a recent incident stemmed from its native Cardano web wallet generation software, with preliminary losses estimated at approximately 16 million ADA. The platform engaged an independent blockchain security firm for technical review and collaborated with Input Output, Cardano Foundation, Intersect, and SundaeSwap to monitor exchange flows. Between June 21 and 23, 2026, a sophisticated automated attack drained funds across multiple wallets in four distinct events, with external threat actors responsible for three of them.
SecondFi identified two attackers and secured approximately 129 million ADA through emergency rescue measures, routing the funds to an independent qualified third-party custodian. SlowMist founder Cos flagged that user losses may exceed $20 million USD or 129 million ADA, noting continuous attack activity over more than 30 hours alongside other stolen tokens. The company patched the vulnerability, advised users not to restore recovery phrases into other Cardano wallets, and directed affected users to submit claims through a designated link while an external accounting firm was engaged for special audit verification.
What remains unclear is the full scope of tokens beyond ADA that were stolen, the timeline for fund recovery through the custodian arrangement, and whether additional vulnerabilities in the wallet generation software may surface.