← Radar

Incident case file

Sign in to watch

SecondFi — Cardano Wallet Nonce-Derivation Key Compromise

Incident date June 21, 2026

1 views

ContainedCardanoWallet key compromise (predictable key generation)Cluster: SECONDFI-KEY-2026-06

Estimated loss

$2.4M

Victims identified

374
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Attacker: Attacker — hub & token vault (A1): addr1q8g8cgwqw98q2mrzrwgcy3wectdxwem8a8zp9r2mn6wjy7q4x7gcpv39wwurj7n72akw4kd0dgmv72gz4j92fvhn29ss7vuz99. Attacker — dormant ADA vault (A2): addr1qxd39k4peszxlf0x59e88hngpe5u9882y2lyhdzazsq4kfvmztd2rnqyd7j7dgtjw00xsrnfc2ww5g47fw6969qptvjshwxpl3. Collector 1 (stake): 52838a79...6497c5. Collector 2 (stake): 1dde43d2...2ab60c. Collector 3 (stake): 8bd0c0f7...6afe292f. Fee/gas funder: addr1q8acx4h5a38x6ekpsp0x7aelw6mflt78khmz8lz75rtnqvn07w88zx2e89tgzqr3x0mecngql

Funds moved to: Wave 1 (June 21, 2026, 20:29:41 UTC ignition): ~12.3M ADA + hundreds of token types drained directly from ~198 wallets, routed through Minswap V2 and at least one other DEX, dissolved into ordinary trading volume — considered likely unrecoverable (no vault to freeze). Largest single victim drain documented: 38,421.556 ADA (tx 16f81996eb36b5e1863162143a4b308e7979a880422c0129a3e9951346e08814, 20:31:15 UTC). Wave 2 (starting before dawn June 23, 2026): Hub wallet (A1) swept ~2,874 wallets one tra
RECONCILIATION NOTE: two different scopes coexist for this incident. SecondFi's official June 24, 2026 statement attributes ~16M ADA (~$2.4M) across 374 wallets to '3 external draining events' — this is the figure used for feed_summary.amount_lost_usd and victims_identified, since it governs the official claims process at support.secondfi.io. An independent on-chain forensic reconstruction (Bitquery Research, published June 24, 2026) traces a broader pattern: 3,072 wallets drained (198 in wave

Timeline: T0, wave 1 (June 21, 2026, 20:29:41 UTC): Three collector wallets ignite in the same second and begin sweeping long-dormant Cardano wallets (some untouched since 2020) into Minswap V2 and other DEX contracts, draining ~12.3M ADA directly from 198 wallets. T0+2min (20:31:15 UTC): Documented victim drain of 38,421.556 ADA. June 21-22: First public community reports of unauthorized drains begin circulating. T0, wave 2 (before dawn, June 23, 2026): Hub wallet A1 begins sweeping ~2,874 additional wallets one transaction at a time, including whale wallets dormant since 2020. June 23, ~03:35-03:48 UTC: Largest individual sweeps into hub A1 recorded (5.41M, 5.20M, 4.71M ADA, etc.). June 23, 11:29:29 and 11:39:14 UTC: Hub forwards two blocks of 60,000,000 ADA each into dormant vault A2 (total 129,430,001 ADA across 7 transactions, opened with a 1-ADA test transfer). June 23, 10:41:09 UTC: A 'SecondFi WhiteHat Exploiter'-labeled address returns 316.20 ADA + 28.30 NIGHT to one victim. June 23, 12:20 UTC: Last movement of vault A2 — dormant since. June 23, 2026: SecondFi suspends operations. June 24, 2026: SecondFi publishes official update — root cause identified (deterministic nonce derivation flaw), patch rolled out for unaffected wallets, ~129M ADA secured via emergency rescue and routed to a third-party custodian pending external audit, claims process opened at support.secondfi.io. SlowMist founder Cos (Yu Xian) independently estimates total user losses could exceed $20M. Bitquery Research publishes full forensic reconstruction the same day. June 25, 2026: SecondFi publishes further root-cause clarification and reiterates the seed-phrase warning (last documented activity).

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)