All news
News··14 min read

Community Update: Unauthorised Transfers from Empowa Treasury Wallets

Empowa has been the target of two connected incidents involving unauthorised transfers from three project wallets. Every wallet address and transaction hash is published in full so anyone can verify each step on a Cardano block explorer.

By the Empowa team

Community Update: Unauthorised Transfers from Empowa Treasury Wallets

All times in this update are UTC, derived from block slot numbers. Every wallet address and transaction hash referenced below is published in full, with verification notes, here: Full transaction sheet. Anyone can check each step on a Cardano block explorer.

Summary

Empowa has been the target of two connected incidents involving unauthorised transfers from three project wallets: a treasury wallet holding ADA, and the two legacy EMP allocation wallets known on-chain as $empowa.public and $empowa.ispo.

Approximately 143,700 ADA was moved out of the treasury wallet between November 2025 and June 2026, along with 36,000 NIGHT tokens from a Midnight airdrop allocation that was registered and redeemed using the wallet's keys without our knowledge. Approximately 4.24 million EMP, the undistributed remainder of the public-sale and ISPO allocations, was moved out of the two EMP wallets between June and August 2026. A portion of that EMP is currently being sold on Minswap.

We are publishing this now for three reasons: so the community hears it from us first; so it is absolutely clear that the sell pressure currently visible on the EMP/ADA pool is not Empowa or any member of the team liquidating tokens; and because transparency about what we know, and what we don't, is the standard we want to hold ourselves to.

No other Empowa wallets are affected. The team, housing, innovation, operating and private-sale allocations were migrated to new custody in 2024 and remain intact and verifiable on-chain. The community's claims record remains intact. This incident does not affect the housing projects or EmpowaPay operations.

Background: how these wallets were set up

Empowa's original wallet infrastructure was created at the project's launch in March 2022 by Phil Lewis, Empowa's co-founder and CTO at the time. His public LinkedIn profile lists that role as running from 2021 to 2024. Establishing the token mint, the allocation wallets and the claiming infrastructure was the CTO's role, and the seed phrases for these wallets were held by him in that capacity. That was normal and appropriate.

A handover of systems and credentials to the current team followed. It ran through 2025, with the final items, including the project's domain names, completed in May 2026. As part of that process, the project's treasury wallets were migrated to new addresses under new custody; the migration is visible on-chain in late 2024.

Two matters from that handover are relevant here.

First, two treasury wallets holding ADA were reported to us as having a technical issue that left the funds locked. The first was eventually unlocked and its funds returned to the project. The second was not. When custody of project systems was transferred to the current team, the seed phrase for this treasury wallet was not handed over; we were told the funds were locked by a technical issue. The project eventually wrote those funds off as inaccessible. That wallet is the treasury wallet at the centre of Incident 1.

Second, the $empowa.public and $empowa.ispo wallets were deliberately left on their original 2022 setup during the migration, because they were deeply integrated into our token-claiming feature and carry the on-chain record of every community claim. They continued to operate on the keys created at launch. Those are the two wallets at the centre of Incident 2.

We are setting out this custody history because it is factual, documented, and necessary for the community to understand the incidents. We are not in a position to state who carried out the transfers described below, and we do not do so anywhere in this update. One point does not depend on who did it, or on anyone's status with the project at any time: no person was authorised to move these assets, and no agreement with anyone, past or present, provided for it.

Incident 1: the ADA treasury wallet

The wallet we had written off as locked began moving on 26 November 2025.

Between 26 November 2025 and 10 June 2026, 143,710 ADA left the wallet in eighteen transfers. The funds took two paths:

  • 120,060 ADA (nine transfers, 4 March to 10 June 2026) went to a single intermediary wallet created on 4 March 2026, the same day the first large tranche arrived. We refer to this below as the hub. Through March, April and May, the hub deposited roughly 100,000 ADA into the Liqwid lending protocol as collateral, typically within minutes of each tranche arriving, and borrowed USDCx stablecoin against it. From 10 June its behaviour changed: instead of depositing, it began converting funds to stablecoin and moving them off the Cardano blockchain through smart-contract burns of USDCx consistent with cross-chain bridge redemptions.
  • 23,650 ADA (nine transfers, 26 November 2025 to 15 April 2026) went to a pooling wallet, and from there through a high-traffic relay into three endpoint wallets. About 9,233 ADA of it still sits in one of those endpoints. The rest passed through, including about 8,148 ADA via a Byron-format address that is probably an exchange deposit.

The five earliest transfers (2,400, 1,800, 1,000, 2,200 and 5,000 ADA between 26 November and 23 December 2025) were small and went only to the pooling wallet. They read as a testing phase. The large tranches to the hub began ten weeks later.

The wallet's Midnight airdrop was also claimed and taken. Wallets holding ADA at the Midnight snapshot of 11 June 2025 were entitled to an allocation of NIGHT tokens, but only if the wallet was registered on the Glacier Drop claim portal between 5 August and 20 October 2025 by signing with its keys. Empowa never registered this wallet. Someone else did, during that window. The tokens then became redeemable in quarters from December 2025. On 20 February 2026, a redemption transaction signed with the treasury wallet's keys collected 48,219 NIGHT from Midnight's distribution contract: a quarter unlocked immediately, three quarters held in a vesting contract tied to the wallet.

Each quarter was then collected as it unlocked and sent to the hub: on 4 March and 17 March, bundled into the same transactions as the first two large ADA tranches, and on 24 June, when the hub first sent the near-empty treasury wallet 10 ADA so it could pay the fee, then received the NIGHT thirteen minutes later. The fourth quarter, 12,054 NIGHT, remains locked in the vesting contract. Its thaw window opened on 6 September 2026, and collecting it will require another signature from the treasury wallet's keys.

Two things follow. An airdrop registration is not a drain; it is someone deciding the wallet's future entitlements belonged to them. And it dates their control of the keys: the registration signature had to be made between 5 August and 20 October 2025, at least five weeks before the first ADA transfer on 26 November. The person holding these keys was using them as their own from the summer of 2025. After the 24 June transfer, the wallet was empty apart from the locked NIGHT.

Incident 1 — where the ADA went. Fund-flow diagram, March to August 2026.

Incident 2: the $empowa.public and $empowa.ispo wallets

The EMP transfers came in two phases.

Phase one, June and July 2026. Three transfers moved 850,000 EMP into a wallet created for the purpose on 15 June: 500,000 EMP from $empowa.public (15 June), then 100,000 and 250,000 EMP from $empowa.ispo (18 June and 21 July). That wallet sold the tokens for ADA on Minswap and VyFi, converted the ADA to USDCx stablecoin, and forwarded approximately 4,810 USDCx onward, to the same hub wallet from Incident 1.

The claiming system's own float financed the seller. This detail is easy to miss and is among the most significant evidence we have, so we want to explain it properly.

Every EMP claim our community ever made was an on-chain transaction, and every Cardano transaction requires a small ADA fee. The EMP in those claims came from $empowa.public and $empowa.ispo, but the fees did not. A third address existed purely for that purpose: an operational "fee-payer" holding a working float of ADA, contributing roughly 2 ADA to each claim to cover the network cost. It performed that one job 2,635 times between November 2022 and August 2026. Anyone can verify this pattern by opening any historical claim transaction: the allocation wallets supply the EMP, the fee-payer supplies the fee, and the claim goes to the community member. It is system plumbing: a petty-cash drawer for the claiming infrastructure.

Now the sequence on the morning of 15 June 2026:

  • 06:01: 500,000 EMP leaves $empowa.public for a seller wallet created in that moment. The new wallet holds the EMP but almost no ADA, and on Cardano a wallet with no ADA cannot transact at all, let alone place DEX orders, which require fees, deposits and batcher payments.
  • 06:09: eight minutes (24 blocks) later, the fee-payer address sends the new seller wallet 95.33 ADA. That float is what subsequently paid for the selling.

That 06:09 transfer was the fee-payer's final outbound transaction. After four years and thousands of claim fees, the last thing the claiming system's own infrastructure ever did was bankroll the wallet draining it.

Why this matters so much:

  1. It shows the claiming system's keys were operated as a set. The EMP transfers show someone held the keys to $empowa.public and $empowa.ispo. This transfer shows the same operator, in the same eight-minute window, also held the key to the fee-payer: the complete key material of the 2022 claiming infrastructure, used together in one sitting. Those three keys were designed to work together and would have been held together, so this narrows the question to who had access to that key material as a set.
  2. It shows planning, not opportunism. The operator anticipated that a brand-new wallet could not trade, and provisioned it, from the system's own float, within minutes. This was a prepared sequence, not a smash-and-grab.
  3. It is hard to reconcile with an innocent explanation. A legitimate migration or authorised consolidation would have no reason to end with the claim system's operational float diverted to an anonymous trading wallet as its final act.

To be precise about the limits of this evidence: it establishes that one party held and operated all three keys together. It does not, by itself, establish who that party was.

Phase two, 28 August 2026. At 10:56 and 10:57 UTC, both wallets were emptied completely: 3,053,763 EMP from $empowa.public and 338,082.71 EMP from $empowa.ispo, into a second newly created seller wallet. Every remaining UTXO was consumed. Nothing was left behind.

From 31 August, that second wallet began selling EMP through the DexHunter aggregator into the Minswap V2 EMP/ADA pool, in 60,000-EMP tranches with a minimum price of 0.030 ADA per EMP. As of 1 September it had sold roughly 120,000 EMP for about 3,785 ADA, held just over 3 million EMP, had around 260,000 EMP in unfilled sell orders, and had moved 3,700 ADA onward to a fresh holding address. This is the sell activity currently visible on the EMP chart. It is not us.

Incident 2 — where the EMP went. Fund-flow diagram, June to September 2026.

The handle NFTs, and why this matters

In the 28 August sweep, the $empowa.public and $empowa.ispo ADA Handle NFTs were not taken with the tokens. They were carefully sent, with 1.5 ADA each, to Empowa's team wallet.

This detail deserves attention. These handles have no realistic resale value to an outsider. An opportunistic thief takes everything in a wallet or ignores worthless NFTs; they do not thoughtfully return the nameplates to the project. Our internal tooling references project wallets by these handles: with the handles re-homed on a live project wallet, our dashboards would not show the drained wallets as anomalous. In our assessment, this step only makes sense for someone with an intimate understanding of how Empowa tracks its on-chain funds, who understood that empty handle-wallets would raise an alarm.

Other technical evidence points the same way. All four transfers out of the legacy wallets, in June and August, carry an identical software artefact (an empty auxiliary-data structure, hash bdaa99eb…5a030c), indicating they were constructed with the same tooling. That artefact does not appear on the team wallet's transactions or on the 2024 treasury migration. And as noted above, the claiming system's own fee float was used to bankroll the first seller wallet. Whoever did this held the 2022 keys and knew our infrastructure well.

This is not the SecondFi / Yoroi incident

Some community members will be aware that SecondFi, the operator of Yoroi wallet services, disclosed in June 2026 that a flaw in its wallet-generation software allowed attackers to reconstruct private keys, with about 16 million ADA taken from several hundred addresses. We looked at this carefully. It does not explain what happened to Empowa's wallets, for four reasons.

  • Chronology. Control of the treasury wallet is evidenced from the airdrop registration between August and October 2025 and the first transfer on 26 November 2025, seven months before the SecondFi incident came to light.
  • Wallet type. The EMP wallets and the fee-payer were single enterprise addresses driven by our claiming backend, not browser wallets generated by consumer software. A wallet-generation flaw does not reach them.
  • Behaviour. An attacker who has reconstructed a key does not register airdrops, wait for quarterly unlocks over eight months, return the project's handle NFTs, or use the claiming system's own fee float. The pattern here is that of someone with lasting, deliberate control.
  • SecondFi's own data. We checked the treasury wallet's stake key, both EMP addresses and the fee-payer against SecondFi's published incident checker. None appears in its list of affected addresses. SecondFi describes that list as preliminary, and we note that caveat, but combined with the three points above it puts the matter beyond reasonable doubt.

The connection between the two incidents

The incidents are linked on-chain beyond reasonable doubt:

  1. The same hub wallet received proceeds from both. The intermediary that received 120,060 ADA and 36,164 NIGHT from the treasury wallet is the same address that received the EMP-sale stablecoin.
  2. Both incidents' funds were bridged out together. On 24 June at 06:59 UTC, the hub burned 3,330.10 USDCx in a smart-contract transaction consistent with a cross-chain bridge redemption. This is not an arithmetic coincidence: the burn transaction's inputs are literally the UTXOs created by three inflows received in the preceding fourteen minutes: 367.67 USDCx from the treasury wallet's NIGHT tokens, 2,427.48 USDCx from the EMP seller, and 534.94 USDCx from a third wallet.
  3. The timing dovetails. The treasury drain's final ADA tranche was 10 June. The EMP wallets were touched for the first time on 15 June. One source of funds ran dry; another was opened five days later.
  4. The hub controlled the treasury wallet's keys as late as 24 June. It funded that wallet's final transaction fee before receiving its tokens, and NIGHT collected from the wallet's airdrop travelled to the hub in the same transactions as the ADA on 4 March and 17 March.

One party's wallet received, managed and disposed of the proceeds of both incidents.

Two incidents, one wallet — every flow. Combined fund-flow diagram, March to September 2026.

What we know, and what we do not

We know, and can prove on-chain, everything described above. What the blockchain cannot tell us is the identity of the person who signed these transactions, and we make no claim about that identity in this update. What we can say is this: the transfers were not authorised by Empowa; they were carried out by someone holding keys created at the project's founding in 2022; and the perpetrator has, to date, used only decentralised protocols with no KYC: DEXs, a lending protocol, and a cross-chain bridge.

That last point is also their weakness. Funds must eventually reach an off-ramp. On 19 August, 11,750 ADA moved from the hub to a Byron-format address that is, in our assessment, probably a centralised exchange deposit address; it was forwarded within days. Centralised exchanges hold KYC records and respond to lawful requests.

What we are doing

  • We have engaged professional blockchain investigators, and the full transaction record, every wallet and hash as published in the linked sheet, has been handed to them.
  • We are monitoring all identified wallets in real time, including the ~3 million EMP not yet sold and the 12,054 NIGHT still locked in the treasury wallet's vesting contract, which became collectable from 6 September 2026 and which the key-holder will need to sign for.
  • We will pursue KYC disclosure through legal channels at every off-ramp the funds touch.
  • The claiming system's remaining infrastructure has been reviewed and secured; no other wallets share the compromised keys.
  • We will update the community as the investigation progresses and as legal steps allow.

What this means for you

  • Do not interact with the wallets listed in the transaction sheet, and do not attempt to trade "against" the seller. The EMP/ADA pool is thin and this activity may continue for some time.
  • Empowa will never DM you about this incident, ask you to migrate tokens, or ask for your seed phrase. Expect scammers to exploit this news.
  • We ask the community not to harass or accuse any individual. Attribution is a matter for investigators and, ultimately, legal process. Speculation aimed at individuals could compromise both.

How to verify this yourself

Every claim in this update rests on public blockchain data. The linked sheet lists each transaction with its full hash, the sending and receiving addresses, the amount, and a note on what to look for. Paste any hash into cardanoscan.io or another Cardano explorer. For the 24 June link between the incidents, open transaction 847032d6…4429f1a, select the UTXOs tab, and compare its inputs against the three transactions listed immediately before it in the sheet.

We built Empowa's claiming and treasury records on a public blockchain, and today that is our greatest asset: every movement described above is permanently recorded, verifiable by anyone, and cannot be erased. We will follow it to the end.

The Empowa Team

Full transaction sheet