SECONDFI news
Curated crypto headlines with the on-chain context most tools skip. Written by the team behind Koinlytics.
Alladawallet-securitysecondfied25519zilclient-side-signingnonce-bugzilliqa-ledgerschnorr-signaturesethcardanorfc-8032beosin
Zilliqa Fixed 64 Bits Of The Nonce At Zero. SecondFi Left The Secret Out Entirely. Two Chains, Same Bug Class, One Day, Seven Years Of Signatures
On July 21 and 22, 2026, two independent wallet providers disclosed the same class of bug: nonce generation broken in a way that leaks private keys through public chain data. One drained 16.1M ADA. The other exposed every ZIL Ledger signature since 2019.
SecondFi Left The Secret Out Of The EdDSA Nonce. Every ADA Signature It Ever Published Handed The Private Key To Any Chain Observer. 16.1M ADA Gone
SecondFi's Cardano wallet client derived its Ed25519 signature nonce from only the public transaction hash, omitting the secret half RFC 8032 requires. Every signed transaction leaked the private key to any chain observer. 16.1M ADA drained from 374 wallets over four events.
Follow every move that matters to your bag.
Track your portfolio, LP positions and impermanent loss live. Join Koinlytics and see what moves the market before it shows on Twitter.
Join Koinlytics
Koinlytics