Mystery deepens over Cardano wallet’s $18.5M white hat hacker
Cardano founder Charles Hoskinson has claimed that the identity of the presumably white hat hacker who took $18.5 million worth of ADA from exposed Cardano wallet users is unknown. In an X talk yesterday called The Bingo...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Cardano founder Charles Hoskinson has claimed that the identity of the presumably white hat hacker who took $18.5 million worth of ADA from exposed Cardano wallet users is unknown.
In an X talk yesterday called The Bingo Hall, Hoskinson claimed that he was informed by “Jer” of what went down in a meeting between the Cardano governance firm Intersect and the developers of SecondFi, Emurgo.
A clipped snippet of the talk shows Hoskinson claiming that “A member of the Emurgo team said the identity of the white hat hacker is not known to Emurgo.” He shortly added, “or at least [Emurgo] said it is not affiliated with Emurgo.”
“That’s probably a fair representation of the statement,” Hoskinson said, before noting that it was a secondhand recollection from the meeting by Jer.
For everyone's sake I hope this is nothing more than miscommunication.
I do think that Emurgo should address this statement ASAP though. https://t.co/3D8eoDgcCO
Read more: Cardano wallets drained of $2.4M after self-custody exploit
He said, “I don’t particularly care if it’s Joe Schmo, Emurgo, or a third-party, doesn’t matter to me,” noting that his only concern is how they are going to move the funds and return them to affected users.
Days before this, X users had already begun to speculate whether or not Emurgo knew who the white hat hacker was.
Now, X users are doubting whether Emurgo knew the white hat hacker, with some calling for a police investigation into the firm. Others, however, are hoping Hoskinson’s claims are just a “miscommunication.”
SecondFi claims it triggered emergency measuresSecondFi, one of the largest Cardano wallet generators, was exploited earlier this week, and 16 million ADA ($2.4 million) was reported stolen from user wallets.
However, another 129 million ADA ($18.5 million) was also taken, but SecondFi later claimed that it was the result of an emergency measure it had deployed to secure the funds.
It said, “To prevent total loss during the active exploit, emergency rescue measures were triggered to secure the available ~129m ADA and continues to be routed to an independent, qualified third-party custodian, where they are held securely for the benefit of the affected wallet addresses.”
“An external accounting firm has been engaged for a special audit to independently verify those holdings,” it added.
Intersect’s latest post on the exploit yesterday demanded “a transparent account of how the issue arose, of the emergency measures taken to protect user assets, including the movement of at-risk funds to custody, and of how those assets, which include CNTs and NFTs as well as ada, will be safeguarded and returned.”
Intersect stresses Cardano blockchain isn’t brokenIntersect stressed that the exploit has nothing to do with the Cardano blockchain itself.
However, it noted that the implications of the exploit may impact the flow of ADA across the ecosystem.
SecondFi’s latest statement claims it took a final balance snapshot today and estimates thait will return lost user assetsed in two weeks’ time.
Recovery Process Update
Our team remains focused on returning assets to affected users, and we are making strong progress on a structured recovery and verification process.
Two important updates today:
1. The final balance snapshot has been taken today, Friday 26 June 2026.…
Read more: Hoskinson wants to save Cardano’s rep by leaving X for Discord safespace
This isn’t guaranteed, and the firm noted that it is still trying to reach a “working solution” before it proceeds to test and review the asset return process.
It still advises users not to move to new wallets and warns, “Independent actions taken outside of official guidance create additional risks, and may significantly complicate the asset claims process.”
Protos has reached out to Emurgo for comment and will update this piece should we hear anything back.
Got a tip? Send us an email securely via Protos Leaks. For more informed news and investigations, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.
The post Mystery deepens over Cardano wallet’s $18.5M white hat hacker appeared first on Protos.
Why this matters
Cardano is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on ProtosRelated market context
Cardano News: CIP-0113 Upgrade Could Change ADA Future
Good news coming from The Cardano Foundation as it launched CIP-0113 on mainnet, giving issuers of regulated stablecoins, funds, a...
Cardano Brings Compliance Rules On-Chain With CIP-0113 Launch
TL;DR: Cardano’s CIP-0113 programmable token standard is now live on mainnet. It gives issuers the ability to build controls such...
Trust Wallet integrates MoonPay so US users can buy crypto without leaving the app
The integration enhances user convenience and self-custody appeal but raises concerns about dependency on a single provider's stab...
S&P brings ratings-style scrutiny to $10 billion crypto vault market as $6 million Base incident exposes risks
S&P Global is bringing ratings-style risk assessments to crypto lending vaults as the fast-growing market confronts fresh security...
Cardano’s Programmable Token Standard Goes Live With Built-In KYC and Freeze Controls
The Cardano Foundation announced on Wednesday at TOKEN2049 that CIP-0113, Cardano’s programmable token standard, is live on Cardan...
US Government Moves $103 Million in Seized Bitcoin and BNB, But Hasn't Said Why
Government-labeled wallets sent 833.6 BTC to Coinbase Prime deposit addresses and shuffled 40,285 BNB. No sale is confirmed, but t...