SecondFi: The root cause of the security incident lies at the address level. Users are advised not to restore seed phrase to other wallets.
Related
Base's review of the network outage incident: User funds were secure; the root cause was a vulnerability in the sorter's block construction logic.
According to Mars Finance, on June 27th, the Base engineering team released a recap of the block production outage incident on June 25th, stating that the Base mainnet experienced two block production outages on June 25th and 26th. The first incident occurred at 11:47 AM Eastern Time on June 25th, lasting 116 minutes; the second occurred at 11:28 AM on June 26th, lasting 20 minutes. The root cause of both incidents was the same. Chain integrity was unaffected, and all funds on Base were safe. Block production resumed safely after the team mitigated the incident. The root cause was a vulnerability in the sorter's block building logic, which resulted in expired log states not being cleared after a transaction verification failure. An invalid transaction was received by the block builder and failed to execute as expected, but the system incorrectly retained the log state containing accessed accounts and storage slots. Subsequently, a valid transaction was executed before the log state was properly cleared, causing a gas billing mismatch, which in turn generated a sorted block containing invalid state transitions. Other nodes could not accept this block, causing the chain to stop completely. During the incident, Base was unable to produce new L2 blocks, the orderer and validator nodes were unable to proceed beyond invalid blocks, and new transactions could not be added to the chain. The team fixed the outage by applying a patch to the orderer to ensure that the log state was correctly updated during execution. Base stated that it will strengthen its protocol fuzzing and load testing tools to more easily identify adversarial transaction patterns that may expose similar vulnerabilities, and will continue to improve its operational and monitoring capabilities.
SecondFi has released an update on the latest theft incident: "Isolation Mode" will be launched this week, and a secure wallet export function is planned for release next week.
PANews reported on July 8th that SecondFi, the Cardano wallet service provider, released an update on the latest theft incident, stating that an "isolation mode" will be launched this week, allowing users to check if their wallet address is involved in the incident and submit a support ticket. Next week, they plan to launch a secure wallet export function, providing a safer wallet migration path for users of different skill levels. SecondFi reiterated that it will provide potential asset recovery solutions for wallets confirmed to be affected through its process, expected to be through zero-knowledge proof-based recovery tools with defined eligibility and terms. The official statement also emphasized that they will not request private keys or seed phrase, and users should only operate through the official website support and designated checking tools.
Gnosis Pay Security Incident Recap: Vulnerability stemmed from a flaw in signature verification logic; fix completed.
According to Foresight News , Gnosis Pay released a post-incident report on June 1st, disclosing that the root cause of the vulnerability was a flaw in the ERC-1271 signature verification logic within the Zodiac module: the system only reads the contract's return result and does not check whether the call was actually executed successfully. Attackers exploited this flaw to deploy a contract that intentionally failed but still returned a "valid" status, forged authorization, and then withdrew funds from accounts not owned by them. This vulnerability was introduced with Zodiac code version 3.4.0 in October 2023 and was patched on June 5th. The report shows that attackers withdrew approximately $1.5 million from 5,281 wallets, including approximately $641,000 in GNO, approximately $453,000 in EURE, and approximately $399,000 in USDC.e; another approximately $300,000 is locked in inaccessible accounts, and the team is exploring recovery methods. Gnosis Pay stated that it will expand its security team, introduce external audits, broaden the scope of smart contract audits, and has completed a complete product rebuild (v2) to improve its security response capabilities.
EMURGO announced that SecondFi, the Cardano wallet that was hacked, will permanently cease operations.
ChainCatcher reports that Cardano's founding entity, EMURGO, stated on Monday that SecondFi, the wallet service that suffered a hack, will not resume normal operations even after a security audit is completed. All users are required to migrate their assets through the official recovery process. SecondFi is a rebranded version of the Yoroi wallet and is described by EMURGO as Cardano's largest wallet provider. According to EMURGO's incident report on June 25th, the service suffered four separate wallet thefts on June 22nd, with 374 addresses compromised and approximately 16 million ADA (worth about $2.4 million at the time) stolen. The team also took emergency measures to recover approximately 129 million ADA. EMURGO stated that compromised wallets should be considered permanently exposed at the address and private key levels, and restoring the damaged seed phrase to other wallets cannot eliminate the risk. EMURGO plans to launch an isolated wallet state inspection tool this week, followed by a secure export tool and an offline migration workshop in Tokyo. They are also building a dedicated recovery fund for the on-chain recovery system, and will return assets to affected users after the external audit is completed.
PyShield: 40 major security incidents occurred in the crypto industry in June, resulting in losses of $75.87 million, a 7.13% decrease compared to the previous month.
According to BlockBeats, on July 1st, PeckShield statistics show that in June 2026, the crypto industry experienced 40 major security incidents, resulting in a total loss of approximately $75.87 million, a 7.13% decrease from $81.7 million in May. The Humanity Protocol attack was the largest security incident of the month, causing approximately $31 million in losses. Attackers transferred and laundered funds through multiple blockchains, including Bitcoin, Solana, Hyperliquid, and BNB Chain, and some of the funds were mixed with those involved in the KelpDAO attack, suggesting a possible connection between the attackers in both incidents. In addition, Aztec Bridge and Aztec Connect were attacked separately in the same month, resulting in a combined loss of approximately $4 million. Other major security incidents include: Syscoin Bridge ($10 million), MEV Bot ($7.5 million), Secret Network ($4.67 million), Polymarket users ($3 million), SecondFi ($2.4 million), TESSERA ($2.4 million), Taiko Bridge ($1.7 million), Token of Power ($1.58 million), Raydium ($1.34 million), and LABUBU/OLPC ($1.1 million).
SecondFi Important Security Notice: A mechanism will be launched early next week to help users check if their wallets have been affected.
According to Foresight News , SecondFi has issued an important security alert, stating that there has been an increase in malicious activity and impersonation attempts related to certain incidents recently. As a precaution, users are advised not to deposit any additional funds into their existing SecondFi wallets until further notice. SecondFi will launch a mechanism early next week to help users check if their wallets have been affected and to provide a secure process for smoothly removing assets from the platform afterward. No user-initiated recovery operations have been initiated at this stage, and users' wallets should remain undisturbed until official recovery instructions are received. SecondFi will not request private keys, seed phrases, or wallet credentials under any circumstances, nor will it ask users to transfer assets. For support, please submit your request only through official support channels.