SecondFi, a self-custody platform built on Cardano, suffered a security breach that exposed user wallets to theft. Attackers drained approximately 16 million ADA, worth $2.4 million at current rates, from an unspecified number of affected accounts.

SecondFi disclosed the incident on X on June 23, stating it had detected a security issue and immediately placed services into maintenance mode to prevent further damage. The platform said it had "contained the issue" and taken "extraordinary steps to protect remaining assets where possible." The phrasing suggests some users may not recover their funds.

extraordinary steps to protect remaining assets where possible.

The root cause lay in SecondFi's native Cardano web wallet generation software, according to the platform's security update. The flaw meant that wallets created through the platform during the affected window had compromised key material from inception. SecondFi has not disclosed the exact window of vulnerability or the precise number of wallets created with faulty keys.

Blink Labs, a Cardano software developer, issued a stark warning: "the wallets generated are all unsafe." The firm advised users to "switch to another wallet immediately," indicating that any ADA held in wallets generated through SecondFi during the exposure window remained at risk.

SecondFi is conducting an independent technical audit with an unnamed blockchain security firm to validate its findings on blast radius and remediation scope. The platform has not announced a timeline for the review or for restoring services.

The breach underscores a core tension in self-custody platforms. SecondFi markets itself as a neofinance tool that gives users control over their keys, yet the underlying software that generates those keys failed to protect them. Users delegated trust to the wallet generation process, and that delegation proved costly.