EMURGO is stepping down from Pentad, the five-member group that coordinates Cardano’s infrastructure funding, following a SecondFi wallet exploit that drained approximately 16 million ADA from 374 wallets. The organization said it is redirecting resources toward recovery efforts related to the breach.

The exploit, which affected SecondFi’s key-generation code, resulted in an average loss of 42,800 ADA per wallet and totaled $2.4 million in drained value. Bitquery’s on-chain investigation confirmed that Cardano’s blockchain processed every transaction as designed, placing the vulnerability entirely within SecondFi’s wallet implementation.

EMURGO’s withdrawal occurs during an active funding cycle. In late 2025, the Cardano community approved a 70 million ADA Critical Integrations Budget. The Cardano Foundation then requested 23 million ADA in Critical Integrations V2 funding for Year 2 support, which covers integrations including Circle USDCx, LayerZero, Pyth, Dune, and native Fireblocks integration. EMURGO’s exit from Pentad leaves the coordination body to absorb its responsibilities among the four remaining members: Input Output, Cardano Foundation, Intersect, and Midnight Foundation.

Governance Activity Continues

Cardano’s governance system, defined by CIP-1694, combines ADA owners, delegated representatives, stake pool operators, and a constitutional committee. Participation begins when a holder selects a governance-compatible wallet. Yoroi, a wallet product with governance integration, allows users to delegate voting power to a DRep, switch to a different DRep, abstain, or select no confidence directly within the interface.

According to CardanoCube’s governance hub data, the network recorded 28 active governance actions, 379 active DReps, and 3,217 votes cast over a 30-day period. Across the same window, cumulative voting power totaled 87.52 billion ADA. The SecondFi exploit’s confirmed loss of 16 million ADA represents 0.018% of that 30-day voting power.

Bitquery’s broader forensic accounting identified 129 million ADA in swept funds across related transaction chains, a figure separate from the confirmed 16 million ADA loss and reflecting extended tracing of fund movement.

Wallet Vulnerability and Recovery

SecondFi’s exploit stemmed from weak randomness in its key-generation code. The vulnerability allowed attackers to derive private keys from public information, gaining access to affected wallets. EMURGO did not disclose specific details about its recovery, migration, or restitution process for affected users.

The incident underscores the distinction between Cardano’s consensus layer, which operated flawlessly during the exploit, and third-party wallet services that users choose to access the network. SecondFi’s failure to implement cryptographically secure randomness in key derivation created a standalone risk unrelated to Cardano’s protocol.