Futures
Access hundreds of perpetual contracts
CFD
Gold
One platform for global traditional assets
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Introduction to Futures Trading
Learn the basics of futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to practice risk-free trading
CFD
U.S. stock CFD derivatives
US Stocks
Access real US stocks and ETFs
HK Stocks
Trade quality Hong Kong-listed stocks
Korean Stocks
SK Hynix
Real Korean stocks and top assets
Stock Futures
High leverage, 24/7 trading
Tokenized Stocks
Backed by real stock assets
IPO Access
Unlock full access to global stock IPOs
GUSD
Mint GUSD for Treasury RWA yields
Stocks Activities
Trade Popular Stocks and Unlock Generous Airdrops
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
IPO Access
Unlock full access to global stock IPOs
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
Promotions
AI
Gate AI
Your all-in-one conversational AI partner
Gate AI Bot
Use Gate AI directly in your social App
GateClaw
Gate Blue Lobster, ready to go
Gate for AI Agent
AI infrastructure, Gate MCP, Skills, and CLI
Gate Skills Hub
10K+ Skills
From office tasks to trading, the all-in-one skill hub makes AI even more useful.
Cardano project SecondFi faces $20m loss warning after flaw
SecondFi, a Cardano ecosystem wallet project, said it has traced a recent security incident to its native Cardano web wallet generation software
Summary
The team said it had contained the issue and paused affected services while it reviewed the full scope.
SecondFi said its on-chain review put the preliminary scale at around 16 million ADA. The team also said it was working with a blockchain security firm on an independent technical review.
SlowMist founder sees larger loss risk
SlowMist founder Cos, also known as Yu Xian, said the damage could be far larger than SecondFi’s early figure. He said the estimate depends on whether two Cardano addresses he tracked are confirmed as attacker wallets.
“The users of this wallet have likely lost over $20 million,” said SlowMist founder Cos in an X post. He said the possible loss may involve more than 129 million ADA and other tokens.
Cos later said the transaction pattern suggested an attacker may have obtained a batch of mnemonic phrases or private keys before moving funds over many hours. He said the transfers appeared to move from larger amounts to smaller ones.
Users wait for final review
SecondFi has not yet released a final technical report or a detailed compensation plan. The project said it would continue to share updates as the independent review confirms the scope and cause.
The case has drawn attention because the issue involves wallet generation, not only a smart contract or front-end error. If key generation fails, wallets created through the affected software may face direct risk.
SecondFi is the successor to Yoroi and was launched by EMURGO as a self-custody neofinance app for spending, trading, earning and saving. Cardano’s official app catalog lists SecondFi as a self-custody platform built by EMURGO.
As previously reported by crypto.news, Cardano has already faced market and ecosystem pressure this month. ADA fell below $0.20 in June, while several Cardano projects and governance fights drew wider attention. At press time, ADA traded at around $0.15, down almost 3% in the past 24 hours.
The SecondFi case adds to a wider run of crypto wallet and platform security issues. In a recent update, crypto.news covered Trezor Safe 7 after Ledger Donjon found a chip flaw, though Trezor said user funds remained safe.
Previously, crypto.news explored Bo Shen’s reopened $42 million wallet hack case. SlowMist had linked that theft to a compromised mnemonic seed phrase, showing how seed phrase exposure can leave lasting recovery problems.
SecondFi users now need to follow only official project channels and avoid support scams. Breach events often trigger fake recovery accounts that ask for seed phrases, private keys or transfers.
The final loss figure remains unconfirmed. For now, SecondFi’s public estimate stands near 16 million ADA, while SlowMist’s Cos says suspected hacker activity could push possible user losses above $20 million.