SecondFi Exploit Exposes Private Keys as ADA Wallet Flaw Puts Millions at Risk
Key Takeaways: According to SecondFi, the flaw involved a deterministic nonce that enabled them to build a private key from the blockchain data of the affected wallet. The first wallet address in use among those affected...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Key Takeaways:
- According to SecondFi, the flaw involved a deterministic nonce that enabled them to build a private key from the blockchain data of the affected wallet.
- The first wallet address in use among those affected is thought to be a super-exposed wallet.
- The team warned users not to restore seed phrases or move assets until official recovery steps are released.
User Score
8.7
Follow us on Google NewsSecondFi has shared new information on its recent security breach, revealing that the attack was not as much a corrupt wallet application breach as the cryptographic signing issue. The disclosure has given the most transparent explanation to date of how the compromised Cardano wallets could be breached.
Important Security Update.
As stated, we have identified the root cause of the incident. It is at the address level.
The affected software signer used a deterministic nonce derivation flaw. Every time an address signed a transaction, it leaked enough information to…
— SecondFi (@secondfiapp) June 25, 2026
Read More: SecondFi Exploit Sparks $20M Loss Fears Across ADA
SecondFi Identifies the Root CauseThe team states that the flaw had appeared in the concerned signing software because of a deterministic nonce derivation bug.
Each time a vulnerable address signed a transaction, it was possible to mathematically reconstruct the private key, using public blockchain information.
From the company, it was indicated that the problem is at the address level. This means that transferring funds from one wallet app to another or entering them into a different wallet won’t eliminate risk.
According to SecondFi, the most common wallet address, which is known as the first address or index 0, is the most vulnerable as it is typically where users have their transactions stored.
Restoring Seed Phrases Does Not Solve the ProblemThe project has repeatedly issued the warning that users should not enter their recovery phrase into another wallet. If you know the wallet address you lost your seed phrase, just recreating that seed phrase will give you the exact same compromised addresses.
SecondFi explained that the funds of users could still be lost if they switch funds from addresses that are compromised.
Staking Rewards May Also Be VulnerableThe team also stated that turning down staking rewards may cause further security risks.
Withdrawals here use stake credentials which can possibly already be compromised. Sometimes the money taken off staking would be automatically redeployed to the default address, that hackers might already have control over.
SecondFi said that competitors who keep track of the mempool could be able to front-run transactions and raid assets as soon as they are confirmed on the blockchain.
Read More: $5.87M Ethereum Exploit Hits TrustedVolumes as 1inch Denies Any Protocol Breach
Recovery Process Remains Under DevelopmentSince the exploit went public, there has been some conflicting information flying around the Cardano community, the company wrote. Some users recommended moving wallets immediately, others suggested funding the other applications on Cardano.
The only official instructions are to make a support request via the project’s support portal, and wait for instructions to recover. The team stated that acting independently may make it more difficult in the future to verify assets and to seek reimbursement.
Security Concerns Expand Beyond Wallet ApplicationsThe latest disclosure suggests the incident may become one of the most serious wallet-level security failures within the Cardano ecosystem.
Earlier estimates linked the attack to millions of dollars in ADA and other tokens. Security researchers previously suggested total exposure could exceed $20 million if additional compromised addresses are included. So far, no vulnerability has been identified within Cardano’s base protocol itself.
The post SecondFi Exploit Exposes Private Keys as ADA Wallet Flaw Puts Millions at Risk appeared first on CryptoNinjas.
Why this matters
Cardano is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on CryptoNinjasRelated market context
Coinkite warns Coldcard Mk3 users of firmware flaw that may have compromised wallet seeds
The firmware flaw highlights the critical importance of robust RNGs in hardware wallets, emphasizing the need for vigilant securit...
Coldcard Firmware Flaw Lets Attacker Drain 594 Bitcoin From Users
An attacker swept roughly 594 bitcoin, worth about $38 million, out of around 500 separate wallets between 01:31 and 01:56 UTC on...
Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen
Bitcoin Magazine Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen The popular Bitcoin hardware wallet...
Coldcard Security Notice Puts Bitcoin Wallet Entropy Risk Back In Focus
A Coldcard security issue has put Bitcoin hardware-wallet safety back under the microscope after reports that a firmware flaw affe...
Coldcard attack: 25 minutes, 500 wallets, $38M in BTC gone
Someone likely used AI to drain almost 600 BTC, worth $38 million, from roughly 500 dormant wallets yesterday as part of a seed ph...
As Ethereum turns 11 years old it hosts $148B in stablecoins, but daily mainnet revenue just fell to $330k
Ethereum turned 11 on July 30, the anniversary of the day users generated and loaded the Frontier genesis block in 2015. In its fi...