
Recovery remains on track after a wallet-generation flaw exposed private keys, draining about 16 million ADA from 374 Cardano addresses and prompting scam warnings, with claims now open and operations still paused pending audits.
SecondFi said it has completed its final balance snapshot and begun processing refunds for users affected by Cardano wallet-draining attacks between June 21 and 23, with claims open through its support portal after the June 26 snapshot. The company said a deterministic nonce derivation error in its software signer let attackers reconstruct private keys from publicly available on-chain data, and its investigation found two separate actors compromised 374 wallets in total. SecondFi said the incident drained about 16 million ADA, estimated at roughly $2.4 million, and it warned users to stay alert for phishing and other follow-on scams as recovery continues. The company and parent entity EMURGO said they have secured about 129 million ADA through emergency measures, while 4.02 million ADA tied to the exploit is being tracked in a monitored collection wallet. Normal operations remain paused pending external security audits and a full security review.