2026-06-23
SecondFi
- An initial statement on a security incident with Second Fi, a wallet product from the founding entity Emurgo, with an estimated impact of about 16 million ada.
- Wallet software works perfectly until it does not, whether from an anomaly, an insider threat, or a hack, and the hard part is that funds are then hard to recover.
- Incident response has three phases, triage, transparency, and verified remedy, and the ecosystem should add a fourth: certification of a core Cardano wallet.
- In the age of AI, attackers use uncensored frontier models to find exotic attack vectors, and insider threats like a North Korean applicant caught on the Lace team are growing.
- IO is not Emurgo, has no ownership or control, did not write the code, and cannot offer a remedy, though it will help with forensics and advice.
- Midnight passports and zero knowledge proofs are part of the longer term answer for more secure wallets and delegated agent authority.
16 entries
Second Fi from Emurgo has had a security incident, per its own tweets isolating the root cause to its native Cardano web wallet generation software.
Emurgo's current estimate is an impact of about 16 million ada, with the platform in secure maintenance mode and a balance snapshot taken.
IO's small incident response team under Jerry Moroney has been in contact with Phil, and it looks like a hack that lost user funds.
Wallet software works perfectly until it does not, failing from an anomaly, an insider threat, or a hack, after which funds are hard to recover.
The legacy world has insurance to cover the downside of disasters, but cryptoland is buyer beware.
Incident response has three phases, triage, transparency, and verified remedy, and Phil's team has the triage under control after 41 hours awake.
The proposed fourth step is a certification of a core Cardano wallet, so bad and malicious code and common attack vectors cannot exist.
In the age of AI, attackers use an uncensored frontier model to crunch for hours and find exotic attack vectors a normal black hat could not.
Insider threats are worse with AI, as when a North Korean applicant tried to join the Lace team and was caught, a problem Kraken and Coinbase share.
The ecosystem also needs insurance products, a collective fund wallet users pay into so a remedy exists when something happens.
The amount is not huge, but that is no solace to those who lost funds, echoing Mt. Gox and the Nomad bridge hack where he personally lost money.
Midnight was built partly to add sophisticated cryptography, and a Midnight passport with zero knowledge proofs gives more secure places to transact.
IO is exploring delegated authority through agents via the OWS standard for fundamentally more secure ways to interact with cryptocurrencies.
The first generation Midnight passport should arrive in 2026 and could become part of a certification stack for Cardano wallets.
IO is not Emurgo: it has no ownership or control, did not write the code, and cannot offer a remedy or take accountability.
IO always errs on transparency, requesting independent third party reports from Emurgo, and will re-audit Lace and its own infrastructure in the age of AI.