SecondFi is shutting down following a $2.4 million theft of Cardano tokens that exploited a vulnerability in its transaction signing software. The breach, disclosed in a security incident update, stemmed from a flaw that allowed attackers to derive private keys from public blockchain transaction data.
The theft represents 16 million ADA tokens and exposed a critical weakness in how the platform's signing software generated transaction nonces. When a nonce derivation function became deterministic rather than random, users' private keys could be reconstructed by anyone with access to the blockchain record of their transactions. SecondFi's infrastructure stored user keys encrypted, but the signing process itself created the exposure.
SecondFi launched in 2022 as an Cardano-native yield protocol operated by EMURGO, the commercial arm of the Cardano Foundation. The platform allowed users to stake and lend ADA. The wallet breach occurred in early July 2026, affecting accounts using SecondFi's transaction signing service. The company discovered the intrusion after unusual token movements and traced the loss to the deterministic nonce mechanism in its signer module.
The shutdown marks the end of a recovery effort that began immediately after the theft. EMURGO initiated refunds from its own treasury in the days following the incident, attempting to restore user funds while investigating the exploit. That process has now concluded with the decision to cease operations entirely. No timeline for asset distribution or final settlement has been announced.

Transaction signing vulnerabilities have appeared repeatedly in cryptocurrency infrastructure. In 2019, Monero's transaction signing process exposed similar nonce-derivation risks before a patch was issued. SecondFi's implementation failed at the level of cryptographic randomness, a foundational requirement in elliptic-curve signing schemes that nearly every wallet and exchange now stress-tests before launch.
The loss is contained to the $2.4 million affected users. SecondFi's total value locked had declined to under $15 million before the breach, down from peak usage in 2024. The protocol's Cardano-only focus limited its cross-chain exposure and meant the theft did not ripple through multi-chain liquidity pools or bridge infrastructure.
EMURGO chose to shut SecondFi rather than rebuild. Cardano's own wallet infrastructure and exchanges using the protocol remain operational and unaffected. The cost to EMURGO of the refund and shutdown is material but does not extend liability to the broader ecosystem.