SecondFi to build two-week recovery tool after $2.4M ADA hack
EMURGO’s SecondFi will build and test a recovery tool over two weeks to return about $2.4 million in ADA taken from 374 wallets in a June exploit.
EMURGO’s SecondFi plans a two-week process to build and test a recovery mechanism to return about $2.4 million in ADA stolen from 374 wallets during an exploit in late June. The company completed a forensic review, validated affected balances and said it identified what it described as a clear recovery solution. The timeline calls for one week to construct the mechanism and a second week for testing before funds are returned.
EMURGO posted that CEO Phillip Pon confirmed the investigation results and urged users not to move funds or act outside official SecondFi guidance. The post warned that no recovery actions requiring user participation have begun and reiterated that the firm will never request private keys, seed phrases or direct wallet access. EMURGO has not published a full technical postmortem, per-user recovery amounts or a detailed claims process.
SecondFi reported four wallet-draining events between June 21 and 23. Three events attributed to external attackers removed roughly 16 million ADA, about $2.4 million at the time, from 374 addresses. In a separate emergency measure, the wallet moved about 129 million ADA to an independent third-party custodian to secure funds away from attackers. An external accounting firm has been engaged to verify those holdings. Affected users may file claims through SecondFi’s support site. The company reported it identified two attacker wallets — one that drained 171 addresses and another that drained 203 — and that about 4 million ADA linked to the theft remains in a flagged collection address under monitoring. Law enforcement has been notified.
A forensic report from Tibane Labs attributed the breach to an Ed25519 signing error in the wallet’s signer. The report says the signer failed to include the per-signature secret nonce required by the Ed25519 standard, leaving that value derivable from public transaction data and allowing a single signature to reconstruct a private key. Tibane reported that an experimental, unaudited software development kit called trantor replaced an audited signer on June 8, and that the first compromised signature appears onchain the same day. The firm described matching the signed Android build to trantor code and recovering private keys from historical signatures to confirm the mechanism. EMURGO has not publicly addressed that attribution or released its own technical breakdown.
Security researcher Taylor Monahan noted that SecondFi used proprietary cryptographic code that was closed source and unaudited. SecondFi rebranded from the Yoroi wallet in April. EMURGO has advised users not to restore compromised recovery phrases into other wallets, saying the vulnerability is triggered when a compromised address signs a transaction and moving a phrase to another wallet does not remove that risk.
The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.








