Overview
- SecondFi says its forensic probe of a June 23 exploit found a deterministic nonce derivation error in its web wallet signer that let attackers reconstruct private keys using only public transaction data.
- The company confirmed about 16 million ADA was stolen from 374 addresses in three waves and said investigators traced the activity to two distinct threat actors who have been reported to authorities.
- SecondFi suspended services and routed roughly 129 million ADA into a third‑party custodian as an emergency measure to protect unaffected funds.
- The firm says it is preparing a refund process and expects to begin returning assets to affected users within roughly two weeks, but final amounts and timing depend on independent audits and the completed reconciliation.
- Users are warned not to restore compromised seed phrases or follow unverified recovery links, to await SecondFi's wallet checker and official instructions, and to note that this case shows wallet implementation errors can expose private keys even when a blockchain itself is secure.