The first incident affected Empowa’s treasury wallet on the Cardano network containing ADA: from November 2025 to June 2026, 143,710 ADA were withdrawn from it. The same wallet held 48,219 NIGHT tokens received from the Midnight project’s airdrop—however, according to Empowa’s representatives, the team was unaware of the tokens’ presence. A quarter of the distributed NIGHT tokens remain locked; an additional signature is required to withdraw them.
Suspicious activity began on November 26, 2025, although the address was initially considered blocked. DeFi platform representatives believe the attacker gained access prior to the first ADA transfers.
Most of the withdrawn ADA coins passed through an intermediate address. From there, an unknown party deposited 100,000 ADA into the Liqwid lending protocol, using them as collateral to borrow USDCx tokens. Subsequently, part of the crypto assets was converted into stablecoins and withdrawn from the Cardano network via cross-chain bridges.
The second incident affected the addresses $empowa.public and $empowa.ispo, where undistributed EMP tokens were held. From June to August, 4.24 million EMP were transferred from these two addresses. According to Empowa, approximately 850,000 EMP were sold for ADA on the platforms Minswap and VyFi, after which the received ADA were converted into USDCx. Notably, 4,810 USDCx were sent to the same intermediate address involved in the first incident with the treasury wallet. Empowa representatives state that a portion of the remaining EMP tokens are still being traded on the Minswap exchange.
The Empowa team distances itself from the June hack of the SecondFi platform in the Cardano ecosystem, where unknown actors exploited a cryptographic wallet vulnerability to steal 16.1 million ADA ($2.6 million) from 374 client addresses. Activity in the project’s treasury wallet was observed as early as November, several months before the SecondFi attack. Additionally, the affected Empowa wallets were corporate, not user-created browser wallets.
The attacker’s activity pattern indicated to the Empowa team that they have controlled the private keys for an extended period. The same individual, who gained unauthorized access to the keys, registered the treasury wallet to participate in the Glacier Drop Midnight airdrop, received NIGHT tokens as they unlocked, and then transferred ADA and NIGHT to other addresses.
Blockchain specialists have been engaged to investigate the incident, and Empowa is also continuing to monitor the affected addresses. The project plans to request client data through official legal channels if the stolen cryptocurrencies end up on centralized exchanges. There is speculation that an insider may be involved in the suspicious transfers, but no evidence has yet been found to support this theory.
Recently, the Liquid Network project was targeted in a cyberattack; unknown actors calling themselves "white hat hackers" withdrew 4,000 bitcoins worth $320 million. Later, the hackers returned 3,400 bitcoins to the network’s wallet, keeping 598 BTC for themselves.


