SecondFi Update: How To Check Your Wallet And Move Safely

Episode by Peter Bui on June 28th, 2026

The SecondFi wallet exposure story has moved quickly, and the latest update is important for anyone who used the affected wallet flow. This episode walks through the official response, what affected users should and should not do, and the community tools now available to help check exposure and move assets more safely.

The key message is simple: if your wallet was affected, treat it as permanently compromised. The safer path is not to reuse the same seed phrase in another wallet, and not to panic-sign transactions without understanding what could be left behind.

What SecondFi And EMURGO Have Said

The latest public statements from EMURGO and the SecondFi support portal confirm that this is being treated as a serious wallet security incident. According to the update covered in the episode, around 16 million ADA was lost during the vulnerability, with roughly US$2.4 million worth of assets taken from the Cardano ecosystem.

There was also a much larger protective response. Around 129 million ADA was reportedly moved into third-party custody so those assets could be secured while the teams work through restoration and reimbursement. The episode frames this as a preventive asset-protection response: without that step, the attacker might have been able to harvest far more from exposed wallets.

SecondFi has also pointed affected users towards a support process, and Peter stresses that users should only use the official support address. Affected users may need to submit a ticket and provide wallet details, but they should never share a seed phrase with a website, application, support team member, or anyone else.

Compromised Wallets Should Stay Compromised

One of the most important parts of the update is the warning that compromised wallets should be treated as permanently compromised. Moving the same seed phrase into another Cardano wallet application does not solve the problem. If the seed phrase or signing flow is compromised, the wallet should be retired and replaced with a completely new wallet.

Peter recommends hardware wallets for long-term security. Users with hardware wallets such as Ledger or Keystone were not exposed through the same hot-wallet path discussed in this incident. For anyone who was using the affected SecondFi wallet setup, the safer direction is to create a fresh wallet and move assets only through a process that handles the edge cases properly.

Why Panic-Moving Assets Can Make Things Worse

A lot of the confusion comes from the fact that moving funds sounds like the obvious response. The problem is that Cardano wallets can include ADA, native assets, staking rewards, stake registration state, change outputs, and other wallet-specific details. A rushed transaction may move only some assets while leaving rewards or tokens behind.

If a user signs a partial transaction from a compromised wallet, the attacker may be able to watch the transaction appear on-chain and harvest whatever remains. This is why some community members warned affected users not to move assets independently until the safer process was clearer.

The episode explains a few examples. A wallet may automatically withdraw staking rewards as part of a transaction, or it may return native assets as change. If those outputs return to the compromised wallet, the attacker may still be able to take them. That is the practical reason behind the repeated message: do not panic, and do not improvise with a compromised wallet.

How Ownership Could Be Proven

Peter also covers technical recovery ideas discussed by Sebastian and others in the Cardano ecosystem. One option is to use zero-knowledge proofs so a user can prove they know the seed phrase without revealing it. Another option relates to Cardano wallet hierarchy, where ownership may be demonstrated using higher-level keys rather than an individual address key.

The point of these methods is to help map affected assets back to their rightful owners without asking users to expose sensitive information. It is a strong example of why transparent on-chain history and careful cryptographic proof systems matter in real recovery scenarios.

Checking Exposure And Moving Safely

The episode highlights Phil’s Wallet Exposure Check, which lets users check whether their wallet address appears to be part of the exposed set. Peter notes that he was not exposed because he does not use Yoroi or SecondFi for these wallets and keeps his funds behind hardware wallets, but he points affected viewers towards the tool because other community members have reviewed it and given positive feedback.

The tool can also help build a safer “Get Me Out of Here” transaction. The process involves creating a brand new Lace wallet, copying the receiving address, and using the tool to create a transaction that aims to withdraw rewards, deregister staking, move native assets, and send everything to the clean address. Importantly, the new wallet is not connected to the app; only the receiving address is pasted in.

As always, users should verify URLs carefully, follow official updates, and avoid giving any site their seed phrase. The SecondFi story is still developing, and recovery details may change as the teams continue their investigation and support process.

Key Takeaways

  • SecondFi says affected wallets should be treated as permanently compromised.
  • Hardware wallets were not exposed in the same way as the affected hot-wallet flow.
  • Users should avoid panic-moving funds from compromised wallets without understanding reward, staking, and native asset edge cases.
  • SecondFi support is collecting affected-user details through its official support portal.
  • Community tools can help check wallet exposure and build safer transactions to a clean wallet.
  • Never share a seed phrase with any support site, app, or person.

Disclaimer: This content is for educational purposes only. Nothing in this article constitutes financial advice. Always do your own research.

Text Transcript

Okay, I’ve got an update around the SecondFi situation and how to possibly mitigate any more risk of exposure in this wallet harvesting event. I think that’s the best way to describe it. We’ve got official statements coming out from EMURGO and also really good ways of actually going through and clearing up your wallet to firstly check if your wallet has been exposed to this vulnerability and then also getting your assets out of that situation in a nice clean way before potential hackers, those harvesters, see your transaction online and actually take things out. So let me go through all these details, explain exactly what’s going on and give you guys all a big update.

So a lot has happened over the last 24 hours. A lot of people have been working on a solution for all this and if you have been just sitting there waiting and not exposing your wallet online with a transaction, then you should be okay. But let’s go through the details here to see what we can do next and what has happened if your assets have been drained without you even entering into your app or anything like that. So this is specifically for SecondFi, the SecondFi wallet and control wallet which SecondFi bought.

And this is from the Yoroi and EMURGO ecosystem. So for those that don’t know, if you’re using a hardware wallet such as a Keystone wallet, one of these hardware devices or a Ledger Nano, you’re okay. If you don’t have one of those, links down below in my show notes so you can actually purchase one and secure your assets. It’s highly advisable that you do it now.

Okay now SecondFi have put out various statements here but overall 16 million ADA was lost during the vulnerability, this hack attempt, and roughly about 2.4 million worth of assets. So 2.4 million was taken from our Cardano ecosystem. In comparison, just as comparison, this morning only, PolyMarket suffered a 3 million front-end exploit from a supply chain attack. This means someone injected some code that the front-end of the website depended on.

So when you build a website, you have the website front-end but then you may have pieces that you borrow from open source libraries or something that someone else built. And somewhere along those lines, something was hacked, something was vulnerable. It had some code that allowed a hacker to inject into it and when they saw that their code was being deployed onto PolyMarket, they executed their code and drained all the assets from PolyMarket. That’s a supply chain attack.

That’s not what happened here with EMURGO and SecondFi. So their official statement did come out and they detailed a whole bunch of things in regards to what has happened and what they’re doing at the moment. And let me just highlight a couple of things. We know how much was taken and this is the exact amount that the hacker took themselves.

There was an additional 129 million which the team there did in regards to withdrawing everything that they knew was exposed within their ecosystem and then storing it to a third-party holder that was looking after all those assets while they sought out this mess and be able to return everything to their rightful owners. If they didn’t do this step, this potential hacker here that got the 16 million ADA and started swapping it for USDM would have had their hands on 129 million eventually and then taken all of that as well. So this was a preventative asset protection response from the SecondFi team to be able to look after and take hold of those assets while they work out a plan to get things back in order.

And I will go into how they’re going to identify everyone’s wallet so they can get all these assets back. So to support this process a dedicated and independently secured restoration fund has already been established forming the foundation of a transparent reimbursement process for affected users. So you will get your assets back for those users that weren’t a part of this initial 16 million. Maybe they’ll get some funds together and reimburse people with that loss to 16 million as well.

I’m not too sure about those details yet but recovery is in process. So in parallel they have also submitted this to the legal authorities as well so there will be legal action taken where they can. Now the wallets here, this is a critical notice that they put out. Wallets compromised during this incident should be treated as permanently compromised.

So if you had your wallet within SecondFi and were using it consider it compromised. You need to start completely new wallets. Highly recommend you get a hardware wallet at this point in time. So for this reason affected users must not independently move assets, restore seed phrases or attempt to migrate compromised wallets to another Cardano wallet application.

Because if you use the same seed phrase that was compromised in SecondFi to another wallet it is still compromised. That’s the whole point here. But there are ways around this and I’ll talk about moving your assets in a moment too. There’s been some clarity with that.

So that’s where we’re at. That’s the official statement. Links down below for you guys who can go through it and get a deeper read through it. But I pulled out the highlights for you all.

Now what about identifying your wallet to be able to get your assets back? What there’s all talk about in the comments in my previous video. People just like freaking out going how the hell are they going to work out which seed phrase, which wallet had what assets and how we’re going to send that back. You can do this all within code and this is the beauty of blockchain.

You can see everything on chain and you can map things backwards as long as you can verify that you own that original wallet. And this is what Sebastian has come up with. A couple of ideas that have been put around. So Sebastian was one of the original engineers that worked on Yoroi about six, seven years ago before starting up his own thing.

And now he is the CTO of Midnight. For those that don’t know him, he’s been an OG in the space and an absolutely brilliant technical mind. This is what he said are two particular ways of being able to prove that the wallet is belonging to a particular person. First off, ZK proofs.

And this is a really good one. So you can prove you know the seed phrase without revealing it. And this works even if private keys have been compromised as long as the seed phrase hasn’t been leaked online. And this is the case with SecondFire.

The seed phrase wasn’t leaked, it just wasn’t secured in that signing transaction. So that’s a good thing. So we may be seeing an application that is being built using ZK proofs, which is a brilliant use of the technology really, where you can sign a message on chain to say that yes, I am the owner of this wallet that got compromised. And this is where I want my assets to be restored to.

And because you can sign that with your original wallet, the hacker can’t do that because they don’t have the seed phrase. You can sign that with the original wallet, tell it where to go, and then they can send those assets and funds back to you. But that’s really good. That’s a brilliant way of doing it.

The other way is the way that Kadano’s wallets work with wallet hierarchy. So wallets derives many different keys from a master key. You can prove ownership by signing with a high level account key instead of elite address key. So that’s just how Kadano wallets work.

They’ve got like a state key, a signing key, you got a derep key, you got all these different types of keys within the wallet itself. And they can use the higher level key, the master key, the original key to go through and sign and prove that you own the wallet as well. So that’s another way of doing it. I like the ZK proof side of things.

It’s a really nice use case for Midnight as well. So we’ll see how this one goes. But there are definitely nice ways of being able to identify who owned what within that massive wallet that owns and is holding everyone’s assets at the moment. So that’s really good to know.

Now, please do follow the account for more up-to-date information. Like I said, this is a continuously developing and emerging, growing and evolving story. So please follow the SecondFi X account for all the information. If your wallet has been compromised, go to their support.SecondFi.io website.

This is what it looks like here. Make sure you’re on the right address, support.SecondFi.io. That’s the website. Sign up with their email address and submit a ticket to say that you’re one of the compromised wallets.

You may be asked for some address details, et cetera, et cetera. Never put your seed phrase online. Don’t send them your seed phrase, for example. So just be aware of that.

Now, there are some nuances in regards to how people are trying to move their assets off the particular wallet at the moment. And because there are so many edge cases, that’s why some people say, don’t move all your assets right now. We know that if you move your assets and you stuff something up in a panic, then you expose that signing key on-chain and allow the hacker to harvest the rest of your assets. So for example, if you were trying to move all your assets on-chain and you could only move half of them in one transaction for whatever reason, then the hacker would see that you only moved half and they come in and take the rest of them.

So that’s what the type of situations and edge cases that they were trying to avoid. So sitting tight and doing nothing kind of saved you because it didn’t expose your key on-chain. The pie here, it mentions all these different edge cases. For example, some wallets will automatically withdraw staking rewards as part of your first transaction and return them to your wallet instead of sending them to the other wallet.

So there’s little things like that. And if you panic and you only send your ADA, your native assets will be returned as change. So there’s lots of different scenarios where you could have stuffed things up, especially with your staking rewards. Sometimes people don’t claim their staking rewards for a year or something like that, and it’s still locked in that staking rewards area and they won’t come out until you do a transaction or withdraw them directly.

And if you don’t and you move all your ADA across and let’s say you move 10,000 ADA over, you might have two or 3,000 ADA rewards still stuck in your wallet and it gets returned to that wallet. The hacker will see that and then take that ADA away. So they didn’t want anyone to have anything left over within their wallet that the hacker could take away and swap and then liquidate. So that’s what they were trying to avoid.

So hence, there were a lot of people saying leave your assets in your wallet, don’t touch them at all. Now, Phil here wrote an app. He was putting a lot of comments out about don’t move your assets, etc. So he is one of these people and it kind of makes sense now that things were finally explained and I kind of get it now.

But he built this app here, IsMyCardanoSeifu. This is it here and what you can do with this one is essentially connect your wallet here. So depending on what you are using, I don’t use Yoroi or SecondFi, thankfully. So I hadn’t been exposed and my wallets are all behind hardware wallets as well.

So I’m completely safe. I didn’t risk any exposure here. But you can connect your wallet, whatever it might be, and run a wallet check. And this will see if your address was potentially a part of this exposed risk with SecondFi.

So run your wallets through this here. It will just check the wallet address to see if it had been in the pool of wallets that had been exposed. And if it had, then what you can do is use Phil’s Get Me Out of Here tool, which will do the complete transaction, which will withdraw all of your rewards, deregister your staking and everything else. It takes care of all those edge cases and will then send everything to a brand new address.

So follow the instructions here. I’ll just talk you through it quickly. So first off, create a brand new wallet within Lace. So they’re pushing Lace Wallet here in this regards.

Lace Wallet is open source, so it has been audited by the community as well. So I think that’s why Phil is suggesting Lace. But create a brand new, completely brand new wallet within Lace. Paste the receiving address in here.

So you’re not connecting your brand new wallet to this app. You’re just saying, this is where I want my assets to go. Paste that in here and then you’ll be able to hit that Get Me Out of Here. It will create a brand new transaction that will send all your assets out.

So thank you, Phil, for building that. Other people have checked out this app as well and have given it the thumbs up. So a lot of other smart people have said that, yes, this is good. It’s done correctly.

So I’m trusting this one here myself as well. Thankfully, I wasn’t exposed to any of this here myself, but there were other people that are part of my stake pool, people delegating to me and whatnot that have been exposed. And I really hope that all of you guys out there can recover from this for sure. The reputational damage for Emurgo and SecondFi is astronomical.

In the grand scheme of things, this vulnerability, this hack is still tiny compared to all of the other hacks in the DeFi space and crypto space in general. It is still fairly small. I know people are hurting and saying, hey, I’ve just lost all my life savings here. I get that.

I understand that. And I really hope you guys recover from all this as well. But anyway, guys, if this was helpful, if you got something out of this, hit the thumbs up, like, subscribe, notification bell. I’ve got YouTube memberships down below.

Supporting the channel is really appreciated. Buy me a coffee, links there as well. Great way to support the channel. And of course, like always, guys, try and stay positive.

I’ll bring you some positive news next week. I promise. I’ll see you in the next video.