小賤狗

115 posts

小賤狗

小賤狗

@pan83727

Katılım Nisan 2023
1.1K Takip Edilen83 Takipçiler
小賤狗
小賤狗@pan83727·
@secondfiapp I have more than one wallet, but it appears that I can only restore one wallet at a time. I also cannot find an option to remove the currently restored wallet and switch to another one. How can I restore and access multiple wallets in SecondFi?
English
18
3
11
861
SecondFi
SecondFi@secondfiapp·
⚠️ SecondFi Is Currently in Quarantine Mode SecondFi is running in quarantine mode. It's the same application, but transactions are disabled. You can view your balance and wallet address only, you cannot send, swap, or move funds. A screenshot is below so you know what to expect. Please protect yourself from scams. Only download SecondFi from our official link: secondfi.io/download Do not accept download links from anyone else, including emails, messages claiming to be from SecondFi. Chrome extension is live, app store is pending store approval.
SecondFi tweet media
English
58
55
119
59.2K
小賤狗
小賤狗@pan83727·
Gate這種中資交易所,發生這種事完全不意外🥴
中文
0
0
0
42
小賤狗 retweetledi
YUTA-Cardano/CPA(DMは全て詐欺)
🚨 SecondFi(旧Yoroi)被害に遭った方へ・まとめページ ✅ 抜かれた資金もEMURGOが保護した資金も、どちらも返還されます ✅ SecondFiは再開しません=全ユーザーが移行必要 ✅ 今週、公式の残高確認・移行サイトが公開予定。それを待つのが安全 ⚠️ 秘密鍵・復元フレーズを聞く相手は全て詐欺 「何をすべき/してはいけないか」を最初の3行で。返還の時期、被害額、7/14東京の対面サポート会場、詐欺の見分け方までFAQで解説。 adatool.net/secondfi-recov…
YUTA-Cardano/CPA(DMは全て詐欺) tweet media
EMURGO カルダノ ADA@Emurgo_Japan

x.com/i/article/2071…

日本語
1
7
35
14.8K
小賤狗 retweetledi
SecondFi
SecondFi@secondfiapp·
🛡 Recovery Process Update Today, we want to share an update across three areas: ⚙️ Returning user assets ⚙️ Moving user assets safely ⚙️ Onchain recovery 1. Returning User Assets - Drained by the attackers: @emurgo_io has funded an Asset Recovery Wallet specifically to return assets to users whose wallets were compromised in the attack. - Secured through our emergency rescue response: These assets are currently protected and accessible. We are in discussion with @IntersectMBO on the appropriate custody mechanism to ensure they are held securely and returned to users. 2. Moving Your Assets Our initial guidance was to stay put which was a deliberate step while we worked to fully understand the attack vector and avoid exposing users to further risk. Following active discussions with the Intersect Security Council, should you decide to move your assets, we recommend creating a new wallet using a hardware wallet only. A hardware wallet is the most secure option available. Important: However, users should NOT delete the SecondFi app under any circumstances. We strongly advise users to retain BOTH the app and their seed phrase, as they will be required to support the asset recovery process currently underway. 3. Onchain Recovery Our team is actively progressing an on-chain recovery solution designed to support the secure return of user assets. Extensive technical assessment has identified this as the most secure and efficient recovery pathway currently available. We are now working closely with a Cardano community-led task force to develop, validate and execute this solution securely. This process is more complex than originally anticipated and may require additional time beyond our previously estimated 2-week timeline. We will continue providing updates as progress continues. Important Security Reminder: SecondFi will NEVER request private keys, seed phrases, wallet credentials, or request asset transfers under any circumstances. We will never DM you first. Any message instructing you to move assets or submit wallet information outside of our verified official channels should be treated as fraudulent. Our official channels are our verified SecondFi X account and support.secondfi.io. For support, please submit a ticket only through our official support channel at: support.secondfi.io Thank you for your continued trust as this work continues.
English
41
42
146
38.8K
小賤狗 retweetledi
yasha
yasha@yashablack·
happy to share some awesome cardano news we've built the strongest infra for algorithmic trading on cardano. no bot can compete with us. we generate up to 50% of cardano on-chain defi activity. now we think about how we can integrate it with our products so that cardano becomes attractive for more liquidity providers and traders across web3. preparing to serve the cardano community. below is our agentic trading strategy management system for a single operator. for now, 25 strategies are running. the rails allow us to expand to 100 strategies during the next month. will keep you posted about the results and next steps for this tech. approach is simple – build smth practical, then scale to the community
yasha tweet media
English
16
33
194
5.5K
小賤狗 retweetledi
LeterTW
LeterTW@LeterTW·
#SecondFi 钱包的事件相信大家已经听说,然而很有趣的是这部分的错误实现是在新版本的钱包中被引入的,问题也并不在于初始的私钥生成部分。 在新版本中,96-byte xprv 被传入普通的 PrivateKey signer,只取前 32-byte kL,丢掉 kR,因此变成使用可公开运算的 H(M) 生成 nonce,由于链上签名满足 S=r+H(R,A,M)·kL mod L,R/S/A/M 都是公开可见的,r 能够由 M 计算得出,所以只要使用新钱包通过受影响路径发送/签署过任意一笔交易就能解出 kL,而拥有 kL 就相当于拥有对应私钥的签名能力。 整个错误都是额外引入的,让人不禁怀疑团队内部的交接状态和整体工程流程。为什么这种重大问题会在一个品牌迭代的过程中被引入?我想也许这个问题会很难有一个合适的答案。
LeterTW tweet media
中文
5
7
51
5.4K
小賤狗 retweetledi
SecondFi
SecondFi@secondfiapp·
🛡️ Recovery Process Update Our team remains focused on returning assets to affected users, and we are making strong progress on a structured recovery and verification process. Two important updates today: 1. The final balance snapshot has been taken today, Friday 26 June 2026. We have been capturing regular snapshots throughout the incident response, and this final one gives us an accurate, verified record of balances to work from as we prepare recovery. 2. Timing of recovery. Behind the scenes, our engineering and security teams have worked around the clock to validate balances and evaluate recovery mechanisms. This has led to a solution where assets can begin being returned, which we estimate is around two weeks away: roughly one week to reach a working solution, then a week of testing and review. Timing may shift as the work continues but our priority is clear: a safe return of funds and getting SecondFi back online responsibly. We will resume operations once we are fully confident the platform is secure and all security reviews are complete and we are determined to get there as quickly as we safely can. For now, the only action required is to submit a support ticket at: support.secondfi.io. We appreciate your continued patience as we work through this process responsibly and will continue sharing updates as progress is made.
English
40
51
209
22.1K
小賤狗 retweetledi
Charles Hoskinson
Charles Hoskinson@IOHK_Charles·
I've begun experimenting how to develop a recovery smart contract that can vend out from a pool of Ada and CNTs using a zero knowledge proof of possessing the 24 keywords that generate a wallet. I'll sync with @Quantumplation @SebastienGllmt and the Midnight team on what is discovered.
English
83
161
1.3K
125.5K
小賤狗
小賤狗@pan83727·
Really?
English
0
0
0
79
小賤狗
小賤狗@pan83727·
My SecondFi / Yoroi Incident I want to share my personal experience regarding the recent SecondFi / Yoroi incident. My seed phrase was originally generated in Daedalus Wallet, not in Yoroi or SecondFi. I later imported that wallet into Yoroi and had been using it for a long time without any issue. However, after I opened the app yesterday, it automatically updated to SecondFi. Shortly after the update, my assets were transferred out without my authorization. This is why I believe the issue may not be limited to newly generated wallets or simply someone guessing seed phrases. In my case, the seed phrase was generated by Daedalus and the wallet was only imported into Yoroi. If other users with imported wallets were also affected, then the incident may involve the updated wallet app, imported wallet handling, local key storage, wallet unlocking, or the signing process after the update. I hope SecondFi / EMURGO can clearly explain whether imported wallets were also at risk, what exactly happened after the update, and what affected users should do next. I am sharing this to help other users understand that this may not be only a “new wallet generation” issue. More transparency is urgently needed. @secondfiapp @emurgo_io
English
24
11
139
10K
大懶貓🐱BigLazyCat
大懶貓🐱BigLazyCat@eric821031·
@0xbAlpha @pan83727 签名数据不能反推私钥的,因为是单向散列函数的哈希运算,应该只有私钥直接的泄露才会出现这种情况
中文
1
0
0
84
小賤狗
小賤狗@pan83727·
Reminder: Until the SecondFi incident is fully resolved, please avoid making any transactions with addresses that have interacted with SecondFi. This includes transfers, staking reward claims, unstaking, swaps, claims, approvals, or any action that requires a wallet signature. If you have used SecondFi for trading, signing, authorization, or other wallet interactions, your address may potentially be affected. The risk is not necessarily tied to the wallet app itself. Even if you switch to another wallet app, restoring the same recovery phrase may still give you the same addresses. If an affected address signs a transaction, it may trigger asset movement or expose the assets to further risk. Please wait for SecondFi to officially announce a safe migration, claim, or asset return process before taking action.
English
0
0
0
116
小賤狗 retweetledi
hix Cardano-SPO |COFFE|(カルダノSPO)
SecondFiの続報から、いろいろ具体的な内容が見えてきたようです。以下にまとめます。 👇 【原因が確定:決定論的nonce導出の欠陥】 これまで「弱いRNG/予測可能なシード」と推測されていた原因が、より正確に特定されました。問題は署名時に使われる「nonce(その都度使い捨てるべき乱数)」の導出に欠陥があったことです。 公式の説明👉アドレスがトランザクションに署名するたびに、その署名から十分な情報が漏れ、公開されているブロックチェーン上のデータだけで、そのアドレスの秘密鍵を数学的に再構築できてしまう。 これは先日のエンジン分析(署名が公開鍵を露出させ、鍵を割り出される)を、さらに精密にした形です。単に鍵が露出するだけでなく、署名のたびに漏れる情報を積み重ねると秘密鍵そのものを計算で復元できる、というのが核心です。ECDSA/EdDSA系で実際に知られている「nonce再利用・弱nonce攻撃」の一種ですね。 【特に危険なのは「最初のアドレス(index 0)」】 新しく具体化された警告です。攻撃を受けた場合、最初の(デフォルトの)アドレス=index 0は、ほぼ確実に露出している。多くのウォレットがデフォルトで使う、あるいは唯一使うアドレスで、ほぼ必ず取引履歴がある。その履歴さえあれば攻撃者が鍵を復元するのに十分だ、ということです。 つまり「過去に一度でも署名したことのあるアドレス」が危ない。署名履歴=漏洩データの蓄積、だからです。 【なぜ復元では回避できないか(改めて確定)】 鍵は復元フレーズから導かれるのであって、アプリから導かれるのではない。同じフレーズを別ウォレットに復元すれば、同一のアドレスが同一の露出状態で再生成されるだけ。危殆化しているのは「アプリ」ではなく「そのアドレスの鍵」そのもの、と明言しています。 【ステーキング報酬の引き出し・委任も危険】 ここが今回いちばん実務的に効く新情報です。報酬引き出しや委任はステーク資格(stake credential)で署名され、引き出した資金が危険なindex 0アドレスに送られる可能性がある。そして、別のウォレットを使って引き出しても同じこと。メンプールを監視する攻撃者にフロントランされ、確定時に掃かれうる。 つまり「報酬を引き出すだけ」「委任先を変えるだけ」の操作すら、危険なアドレスへの資金導線になりうる、ということです。 【つまり、今は何もできない】 コミュニティ内で善意の助言が錯綜しているが、SecondFiの公式手順が出るまで何もするな、と明言しています。そして、勝手に動くと、かえって正規のクレーム(資産返還)の検証が難しくなる、とも警告しています。これは、あなたが先ほどから取ってきた「動かずに待つ」という判断が、公式に正しいと確認された形です。
SecondFi@secondfiapp

Important Security Update. As stated, we have identified the root cause of the incident. It is at the address level. The affected software signer used a deterministic nonce derivation flaw. Every time an address signed a transaction, it leaked enough information to mathematically reconstruct that address's private key from public blockchain data alone. If you were affected by the attack, your first/default address (index 0) is almost certainly exposed. It is the address that some wallets may be using by default or as the only address at all, and nearly always has transactions. That history is all an attacker needs. Please DO NOT RESTORE your recovery phrase into another Cardano wallet. This does not mitigate the security risk. Your keys are derived from your recovery phrase, not from the app. Restoring the same phrase into another wallet recreates identical addresses with identical exposure. The compromised thing is the key of the compromised address(es), not the interface you are using. If you were affected by the attack, and use any of your compromised address(es) to deposit it could be drained again. This includes withdrawing staking rewards even using another wallet. Reward withdrawal and delegation are signed with the stake credential. The withdrawn funds could be routed to your first/default address (as indicated above), which has a high chance of being compromised (wallets work differently managing it). Mempool-monitoring adversaries can front-run or sweep your assets on confirmation. There has been conflicting advice from community members in an attempt to be helpful. Do nothing until official steps come from SecondFi. We are working to facilitate the verification process so users can claim back their assets safely. Following the above is very important, if not it makes verified claims more difficult. The only thing you should do right now is submit a ticket at support.secondfi.io We will never DM you first or ask for your recovery phrase.

日本語
3
8
30
4.7K
小賤狗 retweetledi
SecondFi
SecondFi@secondfiapp·
Important Security Update. As stated, we have identified the root cause of the incident. It is at the address level. The affected software signer used a deterministic nonce derivation flaw. Every time an address signed a transaction, it leaked enough information to mathematically reconstruct that address's private key from public blockchain data alone. If you were affected by the attack, your first/default address (index 0) is almost certainly exposed. It is the address that some wallets may be using by default or as the only address at all, and nearly always has transactions. That history is all an attacker needs. Please DO NOT RESTORE your recovery phrase into another Cardano wallet. This does not mitigate the security risk. Your keys are derived from your recovery phrase, not from the app. Restoring the same phrase into another wallet recreates identical addresses with identical exposure. The compromised thing is the key of the compromised address(es), not the interface you are using. If you were affected by the attack, and use any of your compromised address(es) to deposit it could be drained again. This includes withdrawing staking rewards even using another wallet. Reward withdrawal and delegation are signed with the stake credential. The withdrawn funds could be routed to your first/default address (as indicated above), which has a high chance of being compromised (wallets work differently managing it). Mempool-monitoring adversaries can front-run or sweep your assets on confirmation. There has been conflicting advice from community members in an attempt to be helpful. Do nothing until official steps come from SecondFi. We are working to facilitate the verification process so users can claim back their assets safely. Following the above is very important, if not it makes verified claims more difficult. The only thing you should do right now is submit a ticket at support.secondfi.io We will never DM you first or ask for your recovery phrase.
English
56
69
175
100.9K
小賤狗
小賤狗@pan83727·
@SunnyPunkNoir I did not use the web wallet. My last transaction was through the mobile app (SecondFi), where I only transferred NIGHT tokens to an exchange. That was on Jun 9, 2026 at 3:07:21 PM UTC+8, about 15 days before the unauthorized transfer.
English
3
0
4
656
Sunny 🦹🏻‍♂️
Sunny 🦹🏻‍♂️@SunnyPunkNoir·
@pan83727 have you used web wallet in the last 20 days to send any funds out? then that's what caused the hack.
English
1
0
0
618
小賤狗 retweetledi
SecondFi
SecondFi@secondfiapp·
⚠️ As stated, we have identified the root cause, it is at the address level. Please DO NOT RESTORE your recovery phrase into another Cardano wallet, this does not mitigate the security risk. The security risk occurs when an affected user signs a transaction. In addition, we are working to facilitate the verification process so users can claim back their assets safely so the above is very important, as it makes claims more difficult. There has been conflicting advice from different community members in an attempt to be helpful. Do nothing until official steps come from SecondFi. The only thing you should do is submit a ticket at support.secondfi.io. We will never DM you first or ask for your recovery phrase.
English
52
40
146
36.6K
小賤狗 retweetledi
Pete | Beware of Scammers
Pete | Beware of Scammers@astroboysoup·
Cardano DeFi has the community, the security, and the infrastructure, so why is liquidity still the missing piece? @alphagrowth1 thinks they have the blueprint to unlock $200,000,000 in TVL through their "Cardano Prime" proposal. But with a massive treasury ask on the table, the community needs to see the proof. I pushed them on their 3-phase plan, timeline, and how the funds will actually be controlled. Is this the catalyst Cardano DeFi needs, or is it too big of an ask?
English
11
14
140
5.4K
ScoopDoGG
ScoopDoGG@millionhabibi·
@pan83727 It's totally clear second fi controls all our funds just like a bank , later on this will be acceptable for clarity act
English
2
0
7
805