SecondFi completes final balance snapshot for 374 wallets hit by Cardano key exploit

Source Cryptopolitan

Following the automated attacks that saw funds leave wallets in SecondFi, Cardano’s wallet provider formerly known as Yoroi Wallet, between June 21 and 23, affected users now have something to cheer about. 

SecondFi announced that it has taken a final balance snapshot on June 26 to begin processing refunds for affected users.

According to the company’s investigation, the vulnerability that was exploited was a flaw in its wallet generation software, specifically a deterministic nonce derivation error in its software signer that allowed attackers to reconstruct private keys from publicly available on-chain data.

Have the SecondFi attackers been identified?

According to SecondFi’s investigation, the wallet-draining campaigns were carried out by two separate actors.

One attacker compromised 171 wallets in two waves, while a second drained 203 wallets in a separate sweep, the company disclosed on June 25.

SecondFi says that it is working with law enforcement and partners across the Cardano ecosystem to trace and restrict the movement of stolen assets. Currently, 4.02 million ADA linked to the exploit are being held in a single collection wallet that is being monitored.

Will restoring a seed phrase help SecondFi’s users?

SecondFi informed affected users not to restore their recovery phrases into another Cardano wallet. Compromised keys remain exposed regardless of which software holds them because the vulnerability exists at the address level and not the wallet application layer.

Every transaction signed by an affected address leaked enough information for attackers to derive that address’s private key, according to the company’s June 26 guidance.

SecondFi also cautioned against claiming staking rewards, as it could expose funds to attackers monitoring the mempool for new transactions from compromised addresses.

Recovery fund and containment

SecondFi and its parent entity, EMURGO, have secured around 129 million ADA through emergency containment measures. Those funds are being held pending recovery operations.

Another angle that the company said it is working on is the dedicated restoration fund it set up to reimburse affected users. Also, it said normal operations will not resume until external security firms audit its systems and give the green light to bring its services back online.

For now, SecondFi remains in maintenance mode. But users can already start to submit claims through its official support portal.

ADA currently trades around $0.148, having risen by over 3% over the past 24 hours. It traded at around $0.15 following the exploit, down about 2.9% in the 24 hours after the attack became public.

The token had already fallen more than 54% year to date from $0.42 at the start of 2026.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Bitcoin bears target a $52,000 price level as traders position for a 2026 declineBitcoin crashed to $58,700 on Thursday and now options traders are convinced it will crash as far as $52,000 before the year is over, which would be its lowest level since August 2024. That decline saw Bitcoin fall by almost 52% from its all-time high and left the OG crypto below the $60,000 level, which...
Author  Cryptopolitan
17 hours ago
Bitcoin crashed to $58,700 on Thursday and now options traders are convinced it will crash as far as $52,000 before the year is over, which would be its lowest level since August 2024. That decline saw Bitcoin fall by almost 52% from its all-time high and left the OG crypto below the $60,000 level, which...
placeholder
Iran wants ships to pay for services when crossing the Strait of HormuzIran is trying to turn the Strait of Hormuz into a paid transit system after the ceasefire tied to Trump reopened the waterway. Tehran wants ships to pay for security, safety, and environmental services while crossing the oil route, with officials putting the possible yearly income at about $40 billion for the countries involved, according...
Author  Cryptopolitan
17 hours ago
Iran is trying to turn the Strait of Hormuz into a paid transit system after the ceasefire tied to Trump reopened the waterway. Tehran wants ships to pay for security, safety, and environmental services while crossing the oil route, with officials putting the possible yearly income at about $40 billion for the countries involved, according...
placeholder
OpenAI tilts toward 2027 IPO as Anthropic prepares to list firstOpenAI is leaning toward postponing its initial public offering until 2027, per a New York Times report on June 25 citing people involved in the company’s internal deliberations. The shift represents a reversal from the late-2026 timeline OpenAI has signaled since January, with CEO Sam Altman rejecting any valuation below $1 trillion and CFO Sarah...
Author  Cryptopolitan
18 hours ago
OpenAI is leaning toward postponing its initial public offering until 2027, per a New York Times report on June 25 citing people involved in the company’s internal deliberations. The shift represents a reversal from the late-2026 timeline OpenAI has signaled since January, with CEO Sam Altman rejecting any valuation below $1 trillion and CFO Sarah...
placeholder
SOL Price is Down 20% But Solana Network Activity is Climbing on Meme CoinsSolana (SOL) is down about 20% in a month, and long-term holders keep moving coins onto exchanges to sell, yet on-chain volume, aka Solana network activity, has jumped about 39%.Much of that surge com
Author  Beincrypto
18 hours ago
Solana (SOL) is down about 20% in a month, and long-term holders keep moving coins onto exchanges to sell, yet on-chain volume, aka Solana network activity, has jumped about 39%.Much of that surge com
placeholder
OpenAI Could Reportedly Delay IPO After SpaceX ScareOpenAI executives are reportedly urging caution on its IPO timeline after SpaceX’s turbulent public debut, highlighting risks in mega-AI listings.The development comes as Polymarket traders price roug
Author  Beincrypto
18 hours ago
OpenAI executives are reportedly urging caution on its IPO timeline after SpaceX’s turbulent public debut, highlighting risks in mega-AI listings.The development comes as Polymarket traders price roug
goTop
quote