SecondFi vulnerability raises Cardano wallet security concerns
EMURGO announced that it will withdraw from Pentad, the five-person team responsible for coordinating Cardano infrastructure fund management, and instead focus on recovering funds lost in the recent SecondFi Cardano wallet breach. The breach affected 374 wallets and involved approximately 16 million ADA (worth approximately $2.4 million) in losses. EMURGO\'s current focus is on fund recovery, wallet migration and on-chain compensation.
In addition to financial losses, the incident also raised concerns about Cardano\'s governance ecosystem. The affected Cardano wallets are part of the governance system, and users rely on these compatible wallets to delegate voting rights, vote on treasury proposals, and participate in other decentralized governance functions implemented during the Cardano Voltaire era.
Cardano governance relies on secure wallet
According to Yoroi\'s governance documentation, ADA holders can delegate voting rights to Yoroi\'s delegated representative (DRep) on the Cardano wallet interface, select another DRep, or directly cast abstention and vote of no confidence. Reward mechanisms are also tied to governance participation, making wallet security a top priority for all users.
Pentad continues to advance fund management for Cardano infrastructure construction
Pentad was co-founded by the Cardano Foundation, Input Output, EMURGO, Intersect and Midnight Foundation to coordinate infrastructure spending allocated from the treasury in the Cardano ecosystem. The team is responsible for managing a number of important funding plans, including a 70 million ADA critical integration budget approved at the end of 2025 to support stablecoins, institutional-level ADA custody, cross-chain bridges, pricing oracles and analytical tools. Recently, the Cardano Foundation also proposed allocating an additional 3 million ADA as second-year support for integration projects such as CircleUSDCx, LayerZero, Pyth, Dune, and Fireblocks. As EMURGO withdraws, the remaining four organizations will continue to coordinate the second round of funding allocations.
Bitquery traces the root cause of the Cardano wallet vulnerability
Blockchain analysis company Bitquery found that the vulnerability was caused by insufficient randomness in the SecondFi private key generation process, rather than a vulnerability in the Cardano blockchain itself. All transactions were executed as expected by the network, which suggests that the problem lies entirely at the Cardano wallet level. Bitquery also found more than 129 million ADA funds diverted during a broader forensic investigation, but investigators stressed that this amount should not be interpreted as 16 million ADA stolen from affected users.
EMURGO focuses on Cardano wallet recovery work
The average loss per affected wallet was approximately 42,800 ADA, which was a major financial blow to the victims and highlighted the importance of using a secure Cardano wallet. EMURGO has not yet clarified whether its decision to withdraw from Pentad will be permanent, saying its current priority is to assist affected users in fund recovery, relocation and compensation. At the same time, the Cardano governance system is still operating normally. Despite the security incident, observers remain concerned about whether the wallet ecosystem and DRep activities will continue to be engaged.
Conclusion
After the SecondFi vulnerability incident, EMURGO\'s future in Pentad is unclear, but rebuilding user trust is a top priority. As recovery efforts advance, this incident is likely to drive a more secure Cardano wallet solution, a more stringent audit process, and enhanced network resilience within its evolving governance framework.
Summary of core points
EMURGO quit Pentad after the SecondFi Cardano wallet vulnerability incident. The vulnerability affects the wallet layer, not the Cardano blockchain itself. EMURGO currently focuses on money recovery and wallet security.
Explanation of key terms
Bitquery: blockchain analysis company| Cardano Wallet: A tool to store ADAs and participate in governance| CIP-1694: Cardano Governance Framework| DRep: Governance representative for ADA holders| EMURGO: One of the founding organizations of Cardano| Pentad: Cardano Infrastructure Funding Management Group| SecondFi: Wallet project hit by vulnerability| Voltaire Era: Cardano\'s Governance Phase
Frequently Asked Questions
1. Why did EMURGO withdraw from Pentad? EMURGO exited to focus on post-SecondFi recovery.
2. Has the Cardano blockchain been attacked? No, only SecondFi\'s wallet software is utilized.
3. How many ADAs were stolen? About 16 million ADAs, involving 374 wallets.
4. Why is wallet security important? Because it protects governance participation and the security of user funds.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ADA