SecondFi says 16 million ADA drained from 374 Cardano wallets

SecondFi says 16 million ADA drained from 374 Cardano wallets

Wallet software exposed private keys in a Cardano-specific incident, prompting emergency transfers of 129 million ADA to an independent custodian as outside researchers said total losses could be higher.

ADA

Fact Check
Every element of the claim is confirmed by primary sources. SecondFi's official X account (@secondfiapp) states the platform is in secure maintenance mode and that the root cause was isolated to its native Cardano web wallet generation software, with an independent technical review by a blockchain security firm underway. PANews reports the impact estimate of about 16 million ADA tied to the web wallet generation software, and Crypto Briefing corroborates the ~16M ADA (~$2.4M) figure while noting independent/outside analysis of the blast radius (178 wallets), consistent with the claim that outside estimates point to potentially larger losses.
Summary

SecondFi said a security incident in software used to generate its native Cardano web wallets exposed private keys and led to about 16 million ADA being drained from 374 addresses. The company described the breach as an address-level issue affecting specific wallets rather than the Cardano network, warned users not to restore the same recovery phrase in another wallet, and said emergency measures secured about 129 million ADA that was moved to an independent third-party custodian while audits, claims review and technical investigations continue. Outside on-chain analysis cited by SlowMist founder Cos said total losses could exceed $20 million if two suspected attacker-linked addresses are confirmed, leaving the final scale of the incident under review.

Terms & Concepts
  • private keys: Secret credentials that control access to cryptocurrency funds and authorize transactions.
  • ADA: Cardano's native token.
  • custodian: An independent third party that safeguards assets on behalf of others.