cleartext

Independent, sourced crypto news. No paid placements.

cardano

Emurgo winds down SecondFi wallet, keeping only an asset-recovery team after Cardano exploit

Cardano developer Emurgo says wallet firm SecondFi will not resume operations after a June exploit exposed private keys, drained 16 million ADA to attackers and moved 129 million ADA to an unidentified white hat.

Emurgo, the Cardano development firm behind wallet software SecondFi, said this week that SecondFi "will not resume normal operations, even once the audits are complete," and that its remaining involvement is limited to "a dedicated asset recovery team, tasked solely with returning assets to affected users." The statements were reported by Protos on July 7, citing Emurgo's own July 4 update; Cleartext has not independently seen the full Emurgo statement.

The wind-down follows last month's exploit of SecondFi wallets. According to the figures Protos reports, a "nonce derivation" flaw produced deterministic transaction data that could be used to reconstruct users' private keys. In the drain that followed, roughly 16 million ADA (about $2.4 million) was taken by attackers, while a far larger 129 million ADA (about $18.5 million) was moved by what SecondFi describes as a white hat hacker.

The identity and affiliation of that white hat remain unresolved. SecondFi's July 4 statement says assets secured through its "emergency response" — which involved the white hat — are "currently protected and accessible," and that Emurgo has set up a recovery fund address holding about $2.8 million in ADA. Per Protos, it is not clear whether that $2.8 million consists of rescued user ADA or Emurgo's own funds. No audit of the incident and no recovery plan for users had been published as of Protos's report; a wallet-status checker site was announced but is not yet live.

Key facts

  • Emurgo says SecondFi will not resume normal operations; remaining role is an asset-recovery team only (Emurgo statement, via Protos, July 7).
  • 16 million ADA ($2.4M) taken by attackers; 129 million ADA ($18.5M) moved by a self-described white hat (Protos).
  • Cause cited: a "nonce derivation" flaw exposing private keys via deterministic transaction data (Protos).
  • Emurgo recovery fund address holds ~$2.8M in ADA; composition unclear (SecondFi July 4 statement, via Protos).
  • No incident audit or user recovery plan published yet; status-check site announced but not live (Protos).

The real-world read

One source, and a lot still unconfirmed — read accordingly. The white hat framing is doing heavy lifting: an entity moved $18.5 million, seven times what the "bad actors" took, and its affiliation is openly disputed. Protos notes Cardano founder Charles Hoskinson said, based on an Emurgo–Intersect meeting, that the white hat was unknown to Emurgo — then hedged, "or at least [Emurgo] said it is not affiliated." A firm cannot both claim credit for an "emergency response" that "protected" funds and disclaim the party that moved them; those don't sit together cleanly. Note too the gaps: no audit, no recovery plan, no live status tool, and no explanation of whether the $2.8M recovery fund is user money or Emurgo's. Protos says it has asked Emurgo for comment and had none at publication.

This is news reporting, not financial advice.

Sources

  • Protos (secondary, reputable) — July 7 report on SecondFi's wind-down, exploit figures, the nonce-derivation cause, Hoskinson's remarks, and the recovery-fund address; itself citing Emurgo's July 4 statement and an X Spaces discussion. Sole source for this item; Emurgo had not responded to Protos's request for comment.