← Back to Delta Incident Archive

VERIFIED SECURITY INCIDENT · DCI-2026-005

SecondFi Cardano wallet key-generation flaw

A deterministic randomness flaw in a web signer made private keys predictable. About 16 million ADA was reported stolen; no USD value is included in the aggregate.

Incident date2026-06-30 Attack typeWallet vulnerability SeverityCritical Involved chainsCardano

A predictable deterministic-randomness implementation in SecondFi's web signer allowed some Cardano private keys to be reconstructed. About 16 million ADA was reported moved; the asset amount is excluded from the USD aggregate because no stable incident-time valuation was available.