Futures
Accédez à des centaines de contrats perpétuels
CFD
Or
Une plateforme pour les actifs mondiaux
Options
Hot
Tradez des options classiques de style européen
Compte unifié
Maximiser l'efficacité de votre capital
Trading démo
Introduction au trading futures
Préparez-vous à trader des contrats futurs
Événements futures
Participez aux événements et gagnez
Demo Trading
Utiliser des fonds virtuels pour faire l'expérience du trading sans risque
CFD
Produits dérivés CFD sur actions américaines
US Stocks
Accédez à de véritables actions et ETF américains
HK Stocks
Tradez des actions des actions de qualité cotées à Hong Kong
Actions coréennes
SK Hynix
Tradez de véritables actions coréennes et investissez dans les actifs les plus populaires
Futures sur actions
Effet de levier élevé, trading 24h/24 et 7j/7
Actions tokenisées
Adossé à de véritables actions
IPO Access
Accédez à l'intégralité des introductions en bourse mondiales
GUSD
Mint GUSD pour des rendements de Treasury RWA
Activités boursières
Tradez des actions populaires et débloquez des airdrops généreux
Lancer
CandyDrop
Collecte des candies pour obtenir des airdrops
Launchpool
Staking rapide, Gagnez de potentiels nouveaux jetons
HODLer Airdrop
Conservez des GT et recevez d'énormes airdrops gratuitement
IPO Access
Accédez à l'intégralité des introductions en bourse mondiales
Points Alpha
Tradez on-chain et gagnez des airdrops
Points Futures
Gagnez des points Futures et réclamez vos récompenses d’airdrop.
Investissement
Simple Earn
Gagner des intérêts avec des jetons inutilisés
Investissement automatique
Auto-invest régulier
Double investissement
Profitez de la volatilité du marché
Staking souple
Gagnez des récompenses grâce au staking flexible
Prêt Crypto
0 Fees
Mettre en gage un crypto pour en emprunter une autre
Centre de prêts
Centre de prêts intégré
Promotions
Centre d'activités
Participez et gagnez des récompenses
Parrainage
20 USDT
Invitez des amis et gagnez des récompenses
Programme d'affiliation
Obtenez des commissions exclusives
Gate Booster
Développez votre influence et gagnez des airdrops
Annoncement
Mises à jour en temps réel
Blog Gate
Articles sur le secteur de la crypto
AI
Gate AI
Votre assistant IA polyvalent pour toutes vos conversations
Gate AI Bot
Utilisez Gate AI directement dans votre application sociale
GateClaw
Gate Blue Lobster, prêt à l’emploi
Gate for AI Agent
Infrastructure IA, Gate MCP, Skills et CLI
Gate Skills Hub
+10K compétences
De la bureautique au trading, une bibliothèque de compétences tout-en-un pour exploiter pleinement l’IA
SecondFi Exploit Exposes Private Keys as ADA Wallet Flaw Puts Millions at Risk
Key Takeaways:
User Score
8.7
Read More: SecondFi Exploit Sparks $20M Loss Fears Across ADA
Table of Contents
SecondFi Identifies the Root Cause
The team states that the flaw had appeared in the concerned signing software because of a deterministic nonce derivation bug.
Each time a vulnerable address signed a transaction, it was possible to mathematically reconstruct the private key, using public blockchain information.
From the company, it was indicated that the problem is at the address level. This means that transferring funds from one wallet app to another or entering them into a different wallet won’t eliminate risk.
According to SecondFi, the most common wallet address, which is known as the first address or index 0, is the most vulnerable as it is typically where users have their transactions stored.
The project has repeatedly issued the warning that users should not enter their recovery phrase into another wallet. If you know the wallet address you lost your seed phrase, just recreating that seed phrase will give you the exact same compromised addresses.
SecondFi explained that the funds of users could still be lost if they switch funds from addresses that are compromised.
Staking Rewards May Also Be Vulnerable
The team also stated that turning down staking rewards may cause further security risks.
Withdrawals here use stake credentials which can possibly already be compromised. Sometimes the money taken off staking would be automatically redeployed to the default address, that hackers might already have control over.
SecondFi said that competitors who keep track of the mempool could be able to front-run transactions and raid assets as soon as they are confirmed on the blockchain.
Read More: $5.87M Ethereum Exploit Hits TrustedVolumes as 1inch Denies Any Protocol Breach
Recovery Process Remains Under Development
Since the exploit went public, there has been some conflicting information flying around the Cardano community, the company wrote. Some users recommended moving wallets immediately, others suggested funding the other applications on Cardano.
The only official instructions are to make a support request via the project’s support portal, and wait for instructions to recover. The team stated that acting independently may make it more difficult in the future to verify assets and to seek reimbursement.
Security Concerns Expand Beyond Wallet Applications
The latest disclosure suggests the incident may become one of the most serious wallet-level security failures within the Cardano ecosystem.
Earlier estimates linked the attack to millions of dollars in ADA and other tokens. Security researchers previously suggested total exposure could exceed $20 million if additional compromised addresses are included. So far, no vulnerability has been identified within Cardano’s base protocol itself.