Guavy AI Editorial TeamSentiment: -3Clout: 65

SecondFi Halts Operations After Flaw Exposes Private Keys, 16.1M ADA Stolen

SecondFi, a wallet provider, has shut down operations after discovering a critical flaw in its software signer. The deterministic nonce derivation issue exposed private keys through public Cardano transaction data, affecting 374 wallets between June 21 and June 23.

The attackers exploited this vulnerability to steal 16.1 million ADA (approximately $2.6 million) from affected wallets. Fortunately, the incident did not compromise the Cardano blockchain itself.

Investigations revealed that the failure was due to flawed signing logic in wallet software and its handling of Ed25519 signatures.