Attack Update: Two Attackers Locked
Cardano wallet service provider SecondFi released an update on June 25 regarding the recent security breach, confirming that it has identified and isolated two attacker-associated addresses. The attack occurred between June 21 and 23, involving a sophisticated automated campaign executed in three waves that drained funds from hundreds of Cardano wallets. SecondFi stated that it is reviewing all intelligence related to the attack and the individuals involved, and will continue to provide updates.
Attack Details and Fund Tracing
According to SecondFi's disclosure, Attacker A emptied 171 wallets across two batch operations, while Attacker B drained 203 wallets in the third wave. SecondFi released multiple Collection addresses and the stake keys of both attackers. Notably, approximately 4.02 million ADA tokens remain in the designated address of Attacker B; these funds have been flagged and are under on-chain surveillance. The team emphasized that it will continue tracking the flow of funds and collaborate with other security entities.
Impact on Users and Next Steps
Although SecondFi has locked the attackers' addresses, the stolen funds have already been removed from affected wallets. SecondFi advises all users to immediately review their wallet security settings and follow official announcements. The team stated it will fully cooperate with law enforcement and leverage on-chain analysis to recover assets where possible. This incident underscores the growing threat of automated phishing attacks within the Cardano ecosystem, urging users to remain vigilant against suspicious links and unauthorized contract approvals.

