SecondFi Hack Update: What Cardano Users Need To Do
Episode by Peter Bui on June 28th, 2026
The SecondFi incident has been moving quickly, and the most important thing for affected users is to avoid panic-driven mistakes. In this update, Peter walks through the latest official posts, developer commentary, and community analysis around what happened, what users should avoid doing, and why this appears to be a wallet-level issue rather than a Cardano protocol hack.
The episode also covers the white-hat recovery claims, the support process that affected users may need to follow, and the bigger security lesson: hardware wallets matter when meaningful crypto assets are involved.
SecondFi, FUD, And Support Scams
The first warning is simple: be careful of anyone pretending to be SecondFi support. During incidents like this, scammers often rush into replies, DMs, fake support forms, and cloned profiles. Peter highlights the need to follow official channels, including the SecondFi update thread, rather than trusting random recovery advice.
That matters because the wrong action could create more risk. Some early community advice suggested restoring a seed phrase into another wallet and moving funds quickly. The latest SecondFi and developer guidance is more cautious: affected users should not restore their recovery phrase into another Cardano wallet, because the risk is tied to signing activity and address-level exposure.
This Was Not A Cardano Protocol Hack
One of the clearest points in the episode is that Cardano itself was not hacked. The issue appears to relate to the way SecondFi wallets or affected addresses were generated and exposed. Peter references comments from Cardano ecosystem developers, including John Woods and Phil, to separate protocol-level security from a third-party wallet incident.
That distinction is important for the broader ecosystem. A wallet vulnerability can still be serious, especially for users who lose funds, but it is not the same as a failure of the Cardano ledger or consensus protocol. The useful question is what went wrong in the wallet layer and how affected users can recover safely.
What The Exploit May Have Involved
Peter also walks through a technical explanation shared by Max Weber. The core idea is that vulnerable key generation may have reduced the effective search space attackers needed to target. In plain English, if seed or key generation is weakened, attackers may be able to pre-compute or brute-force a vulnerable set far more easily than they should.
On Cardano, addresses reveal only a hash of the public key until a transaction is signed. That means signing can become the moment extra information appears on-chain. If an attacker is watching vulnerable addresses, an attempted rescue transaction may reveal enough for the attacker to act, potentially even front-running the user’s move. That is why “just move fast” can be dangerous in this specific situation.
The White-Hat Recovery Claim
The most surprising part of the update is SecondFi’s claim that four distinct draining events occurred. According to the SecondFi explanation, three were external threat actor events, causing a loss of around 16 million ADA across 374 addresses. A fourth emergency recovery action reportedly secured about 129 million ADA and routed it to an independent qualified third-party custodian for the benefit of affected users.
If accurate, that means much of the frightening on-chain movement may have been white-hat recovery rather than attacker theft. That is still messy. Users will need clear verification, a reliable claims process, and protection from impersonation scams. Peter also points to community interpretations from Giovanni, Paul, and visual tracking from ItsDave.
Hardware Wallets Are The Lesson
The practical lesson is not glamorous, but it is important: use a hardware wallet for meaningful funds. Peter explains why devices such as Keystone, Ledger, and Tangem reduce seed phrase and signing exposure compared with software-only wallets. Hardware wallets are not magic, and users still need to verify transactions carefully, but they can prevent the kind of software-wallet exposure that makes incidents like this worse.
Peter’s strongest advice is to treat security habits as part of crypto participation, not an optional extra. If a wallet holds a serious amount of value, it deserves serious custody hygiene.
Leios And RealFi Updates
The episode closes with more positive ecosystem news. Leios Musashi Dojo is live for testing, giving stake pool operators and builders a way to experiment with Leios testnet infrastructure. Peter also covers RealFi, which is progressing toward testnet with USDR and real-world-asset-backed DeFi products.
So while the SecondFi incident is serious, the broader Cardano ecosystem continues to move. The right response is not panic. It is careful recovery, better wallet practices, and continued scrutiny of the tools people trust with their assets.
Key Takeaways
- SecondFi says the security risk is at the address level and affected users should not restore their recovery phrase into another Cardano wallet.
- The incident appears tied to vulnerable wallet key generation rather than a Cardano protocol-level hack.
- SecondFi reported that external threat actors drained about 16 million ADA, while emergency white-hat measures secured about 129 million ADA for affected wallets.
- Users should rely on official SecondFi support updates and be alert for scammers impersonating support during the recovery process.
- Peter explains why hardware wallets such as Keystone, Ledger, and Tangem reduce signing and seed-phrase exposure risks.
- The episode also covers positive ecosystem updates including the Leios Musashi Dojo testnet and RealFi progress.
Disclaimer: This content is for educational purposes only. Nothing in this article constitutes financial advice or security advice for your specific situation. Always verify official sources and do your own research.
Text Transcript
Alright guys, we’ve got some updates around this second FI situation and if you were affected by this I might have some really good news for you. Now we’ve had some updates from the team and from various community members that are focused on working on this situation to make things right. So let me pull up the posts here, but first off there is a lot of FUD going around, there’s a lot of scams, people trying to jump in pretending they’re second FI support, so please be aware of this. The FUD and some of the social engineering around this might actually trigger the outflows of your assets from your wallet, so this is something to be aware of.
Just sit tight and in most cases you should be okay. But let me go through the details here so you get an idea of what’s been going on. So first off, Cardano wasn’t attacked or hacked directly, so this issue isn’t with Cardano and not the protocol itself, rather the third party wallet. So we just want to make sure that is clear.
Second FI is the issue here and it’s a very specific issue with how the wallets, the seed phrases were generated on that particular app, and this is also including if you imported your seed phrase into the app. And we’ll find out more about that post-mortem of how that particular Cardano address exploit was embedded into the app, but we’ll find out very soon. So this is coming from the second FI account itself and this is the account that you should be following on X, so you get up-to-date information about what to do next. So to provide more clarity, we have to identify the nature of the incident.
It is an address level, it is at the address level. The security risk affected wallets users when a transaction is signed, therefore recovery to another platform or wallet does not mitigate this risk. Do not restore your recovery phrase into a new Cardano wallet. We’ve isolated the affected wallets and we’ll post mitigation steps shortly.
Okay, so that’s where we’re at the moment. There was a lot of advice going around telling people to create a brand new wallet, restore this seed phrase in a brand new wallet, create a brand new wallet, and then just transfer those assets over as quickly as possible. Some people from what I’ve heard have done that and they have their new seed phrase and their assets in that brand new wallet and they’re pretty much okay from what I understand. If you’re using a hardware wallet like a Ledger or a Keystone or a Tangent wallet, you should be totally fine as well because you need that hardware device to sign your transactions to move anything out.
So the hacker couldn’t possibly get that because it’s a physical device that you hold. So those people, those type of situations, you should be totally fine as well. Now here, Phil clarified this. So Phil is probably one of the best developers in the Cardano ecosystem, if not the best.
He jumps on things and thinks differently. So he’s definitely a person to listen to when it comes to things like this. He also mitigated the Minswap situation in the early days of Cardano DeFi. So definitely someone to listen to for this type of thing.
So absolutely do not migrate your seed phrase out of SecondFive to another wallet. Do not sign any transactions at, do not import those else’s phrases. I think he’s meant seed phrases. He’s probably typing with no sleep here.
Don’t import those seed phrases anywhere. If you follow any of the above advice, funds will be safe. If you don’t, you’re putting your funds at extreme risk. Okay, so my advice and what other people say about restoring your seed phrases elsewhere could still have some issues, but I did ask about this to get some clarification.
And some other people did ask if they had already moved their assets out, if there’ll be okay. And most of them said it was pretty much okay. So a little bit of mixed messaging here, but at the moment, if you pretty much do nothing, you should be okay. All right.
So this is the theory around what is actually happening here. And Max, another brilliant developer in the Kedano space, put out this. And let me read through this. What probably happening right now is that it’s not an attack hack anymore.
It’s a harvest. The attacker pre-derived the entire vulnerable key set during key generation from a weak RNG, predictable entropy collapse from keyspace from blah, blah, blah. So basically what he’s saying there is the key that was used to generate all the seed phrases was reduced to something that was really easy to hack, brute force attack it. And it’s supposed to be a two to the power of 256, which makes it really, really hard.
But in this case, they dumped it down to something really easy like A, B, C, D, or something like that. And it made them a computational power for hacking those type of seed phrases really, really easy. So that’s what’s happening here. So now they’re just watching the chain sweeping every address that the moment it moves.
So essentially they’re looking at particular addresses and they say, oh, this one’s active. Let’s go attack that one. They’ve got some assets there and we can brute force that one and then move the assets off. So that’s essentially what they’re doing.
But the problem here also, on Cardano addresses only a hash of your public key. The actual V key is revealed on chain only when you send in a transaction witness. So it’s a bit of extra information that’s put on chain when you actually move assets through the Cardano ecosystem. And that’s what the attacker needed.
They needed to see that V key within the transaction. So they’re watching you move things to be able to get the V key and do the transaction and steal it from you. So signing is the moment you hand the attacker the confirmation, mapping seed, funded address, and even your rescue transactions can get front run in the mempool. And what he means by that is when you submit a transaction to Cardano, it goes to a memory pool that sits on top of the various state pools before the blocks get minted.
So it sits in that mempool and someone could send in a transaction before you get that transaction out quicker than you can to steal your transaction essentially, and then funnel it somewhere else. So this is potentially what the hacker is doing. We still don’t know the details here, but this could very well be what they’re doing. So this is extremely sophisticated and is done by someone that knows Cardano very well for sure.
Okay. So I’ve got some more here. So this is the latest update from SecondFi and this is where the good news comes in. Kind of good news.
It’s a bit mixed here, but this is going to be really interesting to see what comes out of this. So we have identified the root cause and have since rolled out a patch for all unaffected wallets. This will allow us to resume normal operation soon. Now, this is where it gets interesting.
Regarding affected wallets, four distinct draining events occurred. Three were executed by external threat actors, resulting in a loss of 16 million ADA across 374 addresses. Now, when we saw and were watching the ADA being ripped out of the ecosystem, we saw about 130 million ADA. And I was watching this and saw SecondFi post up 60 million ADA.
Is that all? But I’m watching 130 million ADA disappear. And this is where it goes into those details. To prevent loss, total loss during the active exploit, emergency rescue measures were triggered to secure the available 129 million ADA.
And it continues to be routed to an independent qualified third party custodian where they are held securely for the benefit of the affected wallets. So what does that mean? It means SecondFi moved out all your funds to a third party custodian to look after so the hacker couldn’t get it. An external accounting firm has been engaged for a special audit to independently verify these holdings.
We’re working to facilitate the verification process so users can claim back their assets safely. Affected users should submit through support.secondfi.io. Oh my God, this is going to be so messy. So if you had your assets, if you had SecondFi, you were looking at your wallet, you didn’t transact at all, you’re probably fine because the hacker couldn’t see the V key and your transaction appear on chain.
So they weren’t watching, they couldn’t see it, they didn’t know those details and couldn’t move your assets out. But SecondFi used that same vulnerability and exploit to move everything off their connected ecosystem and into a custodial wallet. And now they’re looking at returning everything back to you guys in some way or form. So my God, this is messy, but at least the majority of you guys out there will get your assets back.
I think that’s the best out of this particular situation. There’s going to be still 374 addresses that were completely affected by the hacker themselves and 16 million ADA essentially lost. But maybe that’s the type of value that Emogo could cover out of pocket and get back to you guys. So this could very well be a hack event on the Cardano ecosystem, not Cardano itself, within the ecosystem where everyone’s funds can be returned and covered.
All right, let’s have a look at what else they wrote here. We take this incident seriously and we’re working to ensure all assets are returned to affected users as soon as possible. As said, we have identified the root cause, it is at the address level. Please do not restore your recovery phrase into another Cardano wallet.
This does not mitigate the security risk. The security risk occurs when an affected user signs a transaction. Further explanations to follow. All right guys, so this is definitely a developing story.
So please keep an eye on SecondFi, turn on the notifications there so you get a notification as soon as an update happens. But essentially sit tight, don’t do anything, your funds will be returned according to the SecondFi team here. Now the outcome from this, lots of brand damage, lots and lots of brand damage. Lots and lots of brand damage here.
Anyway, I’ve got some more follow-up posts here. So Giovanni here clarifies this. If I read correctly, Emurgo used the exploit to derive wallets and anticipate the attacker. This way, only 60 million ADAs were stolen by the real attackers, but Emurgo borrowed from affected users so they could eventually return them.
This is an interpretation of the message, but Giovanni, I think you’re completely right there. Now Paul here also clarifies the update, big update for affected users, four distinct draining events, three malicious totaling 16 million, one white hat hacker from SecondFi to secure 129 million of users funds. And it’s Dave here did some really cool visualizations of all of this. And I’d just like to play this video here so you can see exactly what’s going on.
So he mapped it out and tracked the wallets and what was happening here. So we’ve got this SecondFi custodial wallet. We’ve got some seed funding that came in from Binance, the SecondFi wallet. You can see the blue bar there, that one is the hacker’s wallet, and you can see how much ADA went there.
But look at that visualization of that purple blob, which is everyone else that has SecondFi being sucked over to the SecondFi wallet there. Sorry, this isn’t the hacker’s wallet, this is a consolidation wallet where the ADA was moved to. So the green one here is SecondFi’s wallet where they have all of the NFTs, the Cardano native tokens, and the blue one is the consolidated one for just ADA itself. Don’t know why they had to split it like that, but fair enough.
If they’ve got a plan here to manage all this, great. Maybe the blue wallet is the custodial’s wallet and that’s just how they needed to manage things. But anyway, that’s all white hack. That’s the good guys.
If you see all those, it’s because the good guys are holding onto it. It’s been about roughly 24 hours since I watched all of those assets move, but my god, it was a heart-stopping moment for sure when I saw all those assets move out. All right, so we’ve got a lot of posts here about it. I’ll put as many as I can in the show notes down below.
There’s one more here from Sebastian that talks about this. Very good news for everybody affected. Majority of funds were white hack, so they can be returned through official support tickets. Careful of scammers, so be careful.
Beware of scammers. Look at my profile pic. I warn you guys every single day. Now the main things that we can take away from this is hardware wallets.
Everyone should get a hardware wallet. I’ve seen major amounts of assets here from the original hacked and affected users, and I just wonder why they weren’t in hardware wallets. Let me just pull some up for you guys so you can have some references. The first one here is, of course, the Keystone.
This is probably my wallet of choice at the moment. It’s an air-gapped hardware wallet. I’ve got it here somewhere. This is my hardware wallet here.
This is a nice Cardano Press branded one, but this thing here is air-gapped. you don’t plug it into your computer, so that mitigates another risk where you have a man in the middle, you have like a cable that can Wi-Fi transmit your seed phrase out from it. This is completely air-gapped, you never plug into a computer, you can charge it via a battery of some sort and you can use that to scan a QR code on your phone which will sign transactions and it’s a brilliant way of doing it. The user experience is easy, you can use the other device, the other one I love actually using is the Ledger.
I’ve had this since 2017 and it’s a little bit clunkier in the Cardano ecosystem because you have to sign and press so many buttons to sign transactions, but it still is a brilliant wallet. There are some issues with the Ledger recovery side of things where they split your seed phrase off to three different third parties so you can recover from it and that was a forced opt-in, but you know it’s still a great hardware device. The last one I’ll mention is the Tangim. Tangim is a really easy crypto wallet where they have a physical device, in this case it’s their ring, so you can get a ring on your finger and use that to sign your transactions within their mobile wallet.
So that’s a brilliant one as well and if you don’t like the ring you can just get a normal card like a plastic card that’s got a special chip in there that you can scan with your phone with the NFC chip within your phone and sign the transactions that way. So these are three absolutely brilliant hardware wallets and I highly recommend anyone with a substantial amount of crypto assets to get one of these hardware wallets. So definitely a learning lesson for everyone here, hardware wallets are definitely the way to go. Anyone that had a hardware wallet that was connected to SecondFi, they were not affected at all.
So something to take from all of this, learn from so it never will happen to you in the future. In other news, we do have some positive news. The LAOS on Testnet has been launched. The Masashi Dojo has been opened for testing and this is the Testnet network for LAOS, where state pool operators can fire up a LAOS node and then we can start transacting on the network and see exactly how fast transactions are.
So for state pool operators, if you are a state pool operator you can jump on and start playing around with it. If you’re a builder, again you can jump on and start playing around with it as well and we can actually see exactly how fast LAOS is and then see if we can break it as well. So that’s what they’re looking for at the moment, they want to see how fast they can push the LAOS Testnet and see what issues, what bugs may come about from it. So that is some really good news there too.
Some other cool news, RealFi is pushing their DeFi, real world asset DeFi with their USDR stablecoin. They are also approaching Testnet as well and they’re ramping things up for state pool operators. So if you’re a single state pool operator out there between five and I think it was 15 million delegation on your pool, they’re looking for state pool operators to join their network at the moment and I believe they’ll probably be doing an ISPO or something along those lines where they’re distributing tokens through a state pool network. So they’ll be trying to get that state pool network, get people delegated to those particular pools and then reward them in some sort of way.
So that’s what I think they’re doing at the moment. We’ll wait and see what comes about from that, we’ll get more details but these guys here at RealFi are actually delivering what Codano’s mission was supposed to be from day one in 2021, where we’re banking the unbanked. We’re finally delivering that message. We’re looking at real world finance through real world assets backing financial loans and then allowing for real yields through USDR.
So that’s what we’re looking at the moment and it’s really cool to see this coming to fruition and I can’t wait for this one as well. Some good news overall, some bad news with the SecondFi hack obviously, but some really good news in that there is a way out of this and that massive amount of funds that were taken out of the ecosystem were all done by our white hat hacker. So overall really good. We got that, we got Laos and we have RealFi coming really soon guys.
Overall, I don’t know what to think these days. I keep on telling you guys to stay positive so please try and stay positive. There is a white lining on all of this overall in the end. But guys, if you enjoyed this podcast episode, please make sure you hit that thumbs up, that like, subscribe, notification bell on your way out.
YouTube memberships down below, buy me a coffee link there if you want to support me that way, really appreciated. People have been using SuperThanks as well. I never really pushed SuperThanks through YouTube but you can do that as well. I actually have no idea how to do it myself but I’m sure if some others can work it out, you can as well.
And like always guys, stay positive and I’ll see you in the next video.
Comments