2026-06-24

Update

13 entries

After disassembling the minified TypeScript of Second Fi and doing independent forensics, he replicated how the attack occurred.

Cardano Tech & Research

Checking whether the issue is contained to Second Fi or Cardano's crypto supply chain, the open source Cardano cryptographic libraries are not compromised.

Cardano Tech & Research crypto librariesopensource

Key derivation, signature construction, HD wallets, and UTXO selection on the open source wallets appear exactly as before.

Cardano Tech & Research opensource

The anomalous transactions are connected to Second Fi's closed source code, modified from the open source standards.

Cardano Tech & Research opensource

As with Lace and Daedalus, wallet code should always be open source and subject to regular independent audits.

Cardano Tech & Research opensource

Cryptographic code that concerns the whole ecosystem should never be built by a sole vendor, but by a federation that consumes and maintains it.

Cardano Tech & Research

The crypto media claiming Cardano was hacked and all ada is compromised is AI slop, since the protocol, core crypto, and open wallets are fine.

Community & Media artificial intelligence

There is no cryptographic issue and no contagion spreading, so anyone not using that specific company's code has fine funds.

Cardano Tech & Research

If buggy software runs on Windows you do not say Microsoft was hacked, so blaming the Cardano protocol for one application is dishonest.

Community & Media analogy

The 24 seed words do not appear compromised and could be used in a BIP style redemption, though what is derived after them is problematic.

Cardano Tech & Research

Until proven otherwise, treat the Second Fi application as compromised, and the safest move is to leave keys at rest and not transact.

Cardano Tech & Research

IO has no power to freeze or reverse funds by design, because Cardano is a real cryptocurrency like Bitcoin with no intervention mechanics.

Cardano Tech & Research no reversalInput OutputIOHK +2

The issue does not spread to wallets that follow best practices: open source, third party audited, and never modifying cryptographic code.

Cardano Tech & Research opensource