SecondFi, a wallet linked to Cardano founding entity EMURGO, is facing a major security incident after a user reported losing 998,000 ADA from the mobile app. The victim said the wallet was drained without any seed phrase leak and without approving a transaction. Blockchain security firm SlowMist said the broader losses tied to the case may have exceeded $20 million.
A long-time holder says retirement funds were wiped out
X user Jacsam (@j3j30104) posted on July 24 that he had supported the Cardano ecosystem for nine years. He said the stolen ADA had been held as retirement savings inside the SecondFi mobile wallet. According to his account, the seed phrase was written down on paper and kept offline, yet the funds disappeared without warning.
He wrote that most of his capital beyond day-to-day living expenses had been allocated to that position. After the loss, he publicly questioned whether his long-running trust in Cardano and its related official entities had been misplaced.
Wallet generation bug exposed users to key prediction
In an announcement dated July 23, SecondFi said its wallet generation software contained a severe defect. The flaw made it possible for some users’ private keys or seed phrases to become predictable. In practical terms, an attacker may have been able to access affected wallets without obtaining credentials directly from users.
SecondFi’s initial estimate put the impact at roughly 178 wallets and about 16 million ADA in losses. SlowMist later said on-chain tracking pointed to a much larger figure, with potential losses of 129 million ADA plus other tokens and NFTs.
Service suspended as compensation questions remain
SecondFi has suspended its service and placed the wallet into maintenance mode. The team said it has taken snapshots of balances in affected wallets, which may be used as a basis for fund recovery or compensation.
Cardano founder Charles Hoskinson responded by saying the incident was an application-layer wallet problem, not a compromise of the Cardano base protocol. Community reaction has split across two lines: some security-focused users pointed to the danger of keeping large holdings in a connected hot wallet without hardware wallet protection, while others argued EMURGO should take full responsibility for the failure and compensate victims.

