EMURGO, a co-founding entity of Cardano, said Saturday it had mapped a recovery path for users of its SecondFi wallet following an exploit that drained roughly 16 million ADA, about $2.4 million, from 374 addresses between June 21 and 23. CEO Phillip Pon put the timeline at roughly two weeks: one week to build the recovery mechanism, a second to test it before any returns begin. The company has warned affected users not to move funds or take steps outside official guidance, stating the recovery is being built around the current state of compromised wallets. A forensic report from Tibane Labs, a firm building its own wallet, attributed the breach to an unaudited third-party SDK that it says replaced EMURGO's audited signing code on June 8 and left a single signature able to leak a user's private key.

The exploit was isolated to SecondFi's wallet-generation software. EMURGO has identified two attacker wallets and said it moved about 129 million ADA to an independent third-party custodian as an emergency measure, with an external accounting firm engaged to verify holdings. The company said it has notified law enforcement and said about 4 million ADA tied to the theft sits in a flagged collection address under monitoring. According to Tibane Labs, the technical root cause appears to be a third-party SDK integration that created a key-exposure vulnerability when affected addresses signed transactions, though EMURGO has not yet published its own full technical postmortem. SecondFi said the exposure is triggered when a compromised address signs a transaction, and warned that restoring an affected recovery phrase in another wallet does not remove the risk.

For traders, the $2.4 million loss is small relative to total crypto market capitalization, and the two-week recovery timeline suggests EMURGO believes it can make users whole without a broader liquidity event. The market snapshot shows extreme fear at a Fear & Greed index of 18, only marginally above the 30-day average of 17. Funding at +0.4 basis points per eight hours, twice the 30-day average of +0.2bp, points to mild long bias in BTC perpetuals.

The one thing to watch is whether EMURGO's two-week timeline holds. If the recovery mechanism deployment slips or the company revises its estimate of recoverable assets downward, that would raise questions about the completeness of the forensic investigation. A delay beyond two weeks or a reduction in the amount EMURGO commits to returning would suggest the damage is larger or more complex than currently disclosed. For now, the concrete timeline and third-party custodian structure indicate this is being treated as a containable incident with a defined remediation path.

Source: The Block