
Wallet software exposed private keys in a Cardano-specific incident, prompting emergency transfers of 129 million ADA to an independent custodian as outside researchers said total losses could be higher.
SecondFi said a security incident in software used to generate its native Cardano web wallets exposed private keys and led to about 16 million ADA being drained from 374 addresses. The company described the breach as an address-level issue affecting specific wallets rather than the Cardano network, warned users not to restore the same recovery phrase in another wallet, and said emergency measures secured about 129 million ADA that was moved to an independent third-party custodian while audits, claims review and technical investigations continue. Outside on-chain analysis cited by SlowMist founder Cos said total losses could exceed $20 million if two suspected attacker-linked addresses are confirmed, leaving the final scale of the incident under review.