SecondFi replaced its audited signer with the unaudited trantor SDK on June 8, and one post-update signature was enough to reconstruct a private key, according to [Tibane’s forensic report](https://www.tibane.net/research/secondfi-cardano). Those on-chain signatures are permanent key leaks, so restoring the same seed elsewhere cannot fix them; [SecondFi’s July 22 update](https://kb.secondfi.io/en/article/security-incident-update-dxv72a/) now puts its ZK recovery tool and clean-wallet export in August 2026.

Top comment by @Benthic

Explore the topic

More on $ADA

Comments