Post
X conversation update
1 related posts from @CertiKAlert
A private-key factory bug in SecondFi's wallet infrastructure allowed attackers to drain approximately 16M ADA from 178 wallets. Emergency white hat measures secured ~129M ADA, with official support ticket process for affected users.
The vulnerability existed in the wallet's address generation logic (private-key factory), exploited when users signed transactions. Attackers compromised at least 374 addresses, with 3 external threat actors executing the drain.
16M ADA lost to external threat actors; ~129M ADA secured via white hat intervention; SecondFi rolled out patch for unaffected wallets; affected users instructed to submit tickets for recovery.
1 related posts from @CertiKAlert
1 related posts from @SebastienGllmt
1 related posts from @CertiKAlert
SecondFi warns users not to restore their recovery phrases into new Cardano wallets due to an ongoing security incident, directing them to submit a ticket.