SecondFi Recovery: 129M ADA Parked in Custody, 16M ADA Exploit Traced to Wallet-Gen Flaw
374 addresses hit for ~16M ADA ($2.4M); a separate 129M ADA sits with a third-party custodian as Emurgo builds a two-week recovery path.

Two figures define the SecondFi incident on Cardano: roughly 16 million ADA (about $2.4 million at breach time) drained from 374 addresses, and a much larger 129 million ADA moved preemptively into an independent third-party custodian. That second sum currently sits off-chain, generating no yield and untouched by the exploited wallet infrastructure, until verification wraps.
Two-Week Clock, Snapshot-Locked Balances
Emurgo, the team behind SecondFi, says forensic work on the breach is closed and a final balance snapshot has been captured across affected wallets. CEO Phillip Pon said in a Saturday statement that the next seven days go toward building the recovery mechanism, followed by a second week of security testing before any funds move.
That puts first asset movement roughly 14 days out from disclosure. Pon tied the delay directly to preserving wallet states as they existed at snapshot time, flagging that user-side migrations during the window could break the recovery mapping rather than speed it up.
Root Cause: Address-Generation Bug Exposed Private Keys
SecondFi has attributed the exploit to a flaw at the address-generation layer of its Cardano web wallet software, which leaked users’ private keys. No technical post-mortem has been published detailing the exploit mechanics or when the vulnerability entered the codebase, leaving the exposure surface unverified by outside researchers for now.
For on-chain analysts, that’s the open variable: 374 addresses and 16 million ADA is the confirmed loss footprint, but without a disclosed root-cause timeline it’s not possible to independently size whether additional wallets generated by the same flawed process remain at risk before the recovery mechanism goes live.
Custody Overhang and Phishing Risk
The 129 million ADA parked with the third-party custodian dwarfs the 16 million ADA actually compromised, an 8x gap that reflects a containment-first posture rather than confirmed additional loss. Until verification concludes, that capital stays idle rather than circulating through SecondFi or the wider Cardano ecosystem.
Separately on Saturday, SecondFi flagged fraudulent messages impersonating its wallet and targeting users during the recovery window. The company reiterated that no user-facing recovery step has started, that it will never ask for private keys, seed phrases or credentials, and that any instruction to submit wallet data or migrate funds outside its verified support portal should be treated as fraudulent.
Read more: 129M ADA ($18.5M) Drained From SecondFi Wallets, Emurgo Traces Zero Clues
Leave a Reply