
← Learn Cardano Podcast24 Jul · 13 min
SecondFi Hack Update: 16.1M ADA Stolen, Recovery Timeline Explained
SecondFi has released more detail on the wallet security incident that saw about 16.1 million ADA, roughly US$2.6 million, withdrawn from 374 wallets between 21 and 23 June. The update includes a public warning about fake recovery emails, findings from Groom Lake's forensic investigation, and a clearer explanation of the cryptographic flaw involved.
Peter breaks down what SecondFi says happened, including the reported external attacker, the possibility of a second separate attacker, the per-transaction signature issue, and why public transaction data may have been enough to derive affected private key material under certain conditions. The episode also covers the wider discussion around cross-chain wallet code, CTRL Wallet, Yoroi migration, EMURGO tooling and the unauthorised publication of relevant code.
The key safety message is simple: use only official SecondFi channels, do not click recovery emails, never share private keys, and wait for audited recovery and migration tooling rather than trusting anyone offering support through emails, comments or direct messages.
Chapters:
0:00 Fake Recovery Email Warning
1:15 Incident Investigation Update
2:18 Second Attacker Identified
2:56 Cryptographic Root Cause
3:45 Signing Formula Breakdown
5:46 Vulnerable Wallet Library
6:37 CTRL Wallet And Yoroi
8:22 Published Code Question