SecondFi, the EMURGO-backed Cardano wallet platform formerly known as Yoroi, disclosed on June 23 that a flaw in its proprietary web wallet-generation software allowed attackers to drain approximately 16 million ADA ($2.4 million) from 374 wallets across three separate attacks. Blockchain securit...
"SecondFi's wallet software exposed the private keys it generated, and our research has been tracking exactly this move for two years." — Mitchell Amador, CEO, Immunefi
SecondFi, the EMURGO-backed Cardano wallet platform formerly known as Yoroi, disclosed on June 23 that a flaw in its proprietary web wallet-generation software allowed attackers to drain approximately 16 million ADA ($2.4 million) from 374 wallets across three separate attacks. Blockchain security firm SlowMist estimates actual losses may exceed $20 million, encompassing more than 129 million ADA and additional tokens. The vulnerability produced private keys with predictable randomness — an application-layer failure, not a base-protocol compromise.
The incident lands at a structurally weak moment for Cardano. ADA trades at approximately $0.15, a five-year low and a 93% decline from its September 2021 all-time high of $3.09. Network market capitalization has contracted from roughly $100 billion at peak to $5.24 billion. DeFi total value locked on Cardano has fallen 85% from $905 million in late 2024 to under $140 million. The SecondFi breach compounds an already severe confidence deficit in the ecosystem's ability to retain capital.
Between June 21 and June 22, 2026, approximately 200 suspicious transactions were executed against wallets generated through SecondFi's native Cardano web wallet software. On-chain community trackers identified around 178 affected wallets, with attackers draining larger wallets first before working down to smaller ones — a pattern consistent with batch private-key compromise rather than targeted phishing.
SecondFi disclosed the breach on June 23, suspending all platform services and entering maintenance mode. The front-end was paused, a balance snapshot was taken, and an independent security audit was commissioned.
Three distinct attacks were confirmed, collectively draining 16 million ADA (roughly $2.4 million at the time of disclosure) plus an undisclosed number of Cardano native tokens and NFTs. The team executed emergency rescue operations on an additional 129 million ADA, routing funds to a third-party custodian before attackers could reach them.
No stolen funds have been recovered as of June 24.
The root cause was isolated to SecondFi's native Cardano web wallet-generation software — the component responsible for creating new wallets and deriving the private keys that control funds. According to incident reports, the software produced private keys with predictable randomness, enabling attackers who identified the pattern to reconstruct keys for wallets generated through the affected code path.
The vulnerability is address-level, not seed-phrase-level. SecondFi's own advisory confirmed that "recovery to another platform or wallet does not mitigate the risk" — a critical distinction meaning users cannot protect compromised addresses simply by importing their mnemonic into a different wallet application. On-chain transaction patterns analyzed by SlowMist suggest the attacker obtained a batch of mnemonic phrases or private keys and moved funds over many hours in a systematic sweep.
Cardano's base protocol — including the Ouroboros consensus mechanism and the UTXO model — was not the entry point. The failure was entirely within SecondFi's application layer. Blink Labs, a Cardano infrastructure firm, issued a public warning that all wallets generated through the affected software "are all unsafe" and urged users to migrate funds to wallets created by different providers immediately.
This class of vulnerability — flawed randomness in key generation — is well-documented in cryptographic literature but remains rare in production wallet software. Immunefi CEO Mitchell Amador noted the firm had been tracking the pattern for two years, adding that key compromises in DeFi protocols had fallen to 8.1% of total losses by 2025, making this incident an outlier against a declining trend.
The gap between SecondFi's official loss figure and independent analysis is significant.
| Source | ADA Lost | USD Value (approx.) | Wallets Affected | |--------|----------|---------------------|------------------| | SecondFi (official) | ~16 million | ~$2.4 million | 374 | | SlowMist (independent) | 129+ million | $20+ million | 178+ identified |
SecondFi's figure of 16 million ADA ($2.4 million) represents confirmed drains across three attack waves. SlowMist founder Yu Xian (Cos) tracked two suspected attacker addresses and concluded that "the users of this wallet have likely lost over $20M," noting the possible loss encompasses more than 129 million ADA and additional tokens. The discrepancy suggests many compromised wallets remain vulnerable but have not yet been drained — a ticking exposure that could widen the damage if affected users do not migrate funds before attackers return.
An additional complication: secondary scams targeting affected users have already been identified by security researchers, including fraudulent support channels impersonating SecondFi and fake recovery tools designed to harvest seed phrases from panicked users.
The SecondFi breach arrives amid a sustained contraction across Cardano's core metrics.
Price and Market Capitalization:
DeFi Total Value Locked:
Ecosystem Activity:
Yoroi was developed by EMURGO, one of the three founding entities behind Cardano alongside Input Output (IOHK) and the Cardano Foundation. It served over 1 million users as a light wallet — an alternative to the full-node Daedalus wallet — and was widely considered the default entry point for ADA holders who wanted self-custody without running infrastructure.
On April 22, 2026, at Money20/20 Bangkok, EMURGO announced the rebrand of Yoroi into SecondFi, positioning it as a "self-custody neofinance platform" with expanded features for spending, trading, earning, and saving. SecondFi version 10.0.3, the build that shipped the rebranded product, was released on June 7.
Approximately 16 days later, the wallet-generation vulnerability was exploited.
The timing raises questions about the scope and rigor of the security review that accompanied the rebrand. Expanding a light wallet into a full financial platform increases the attack surface substantially. Whether the flawed key-generation code was inherited from Yoroi's codebase or introduced during the SecondFi transition has not been publicly disclosed.
EMURGO has not released a detailed post-mortem. SecondFi stated it is coordinating with the Cardano Foundation, Input Output, Intersect, and SundaeSwap on the response. No compensation framework or timeline has been announced.
SecondFi's immediate actions:
Ecosystem partners:
Charles Hoskinson's response: Cardano founder Charles Hoskinson acknowledged the incident, stating it represents "the sad reality of the industry" while noting the dollar amount was modest relative to other crypto hacks.
Hoskinson's framing — that $2.4 million to $20 million is modest — is contextually accurate against the $755 million stolen across 83 exploits in Q2 2026 alone, according to industry tracking. However, the relative impact on Cardano's ecosystem is outsized: the lower-bound confirmed loss of $2.4 million represents roughly 2.6% of the chain's entire DeFi TVL.
The SecondFi incident surfaces a structural tension in the self-custody wallet market. Wallets are marketed on the premise that users control their own keys — but users implicitly trust the software that generates those keys. A flaw in the key-generation layer breaks the security model at its root, regardless of how robust the underlying blockchain protocol is.
This is not the first wallet-level key-generation failure in crypto history, but it is among the largest in terms of at-risk capital (129 million ADA). The incident will likely accelerate three industry trends:
Third-party audit requirements. Wallet providers face increasing pressure to publish regular, independent audits of their key-generation and signing code — not just smart contracts.
Key-generation standards. The absence of a binding industry standard for wallet key generation leaves each provider to implement its own approach. Efforts to standardize randomness requirements (building on BIP-39 and SLIP-0010) may gain traction.
Ecosystem liability. EMURGO is a founding entity of Cardano. When a founding-entity product fails, the reputational damage extends beyond the product to the chain itself — a dynamic visible in ADA's price response.
The SecondFi breach is a case study in how application-layer failures inflict disproportionate damage on ecosystems already under capital stress. In absolute terms, the confirmed $2.4 million loss is a rounding error in a quarter that has seen $755 million stolen industry-wide. In relative terms, it represents 2.6% of Cardano's entire DeFi TVL — the equivalent of a major bank losing 2.6% of total deposits in a single incident.
The broader question is whether Cardano's ecosystem can absorb the confidence shock. ADA is already at a five-year low, DeFi TVL has collapsed 85% from its peak, and the chain ranks 27th by locked value. The SecondFi exploit does not threaten the Ouroboros protocol, but it damages the one thing a contracting ecosystem cannot afford to lose: user trust in the tools that hold their capital.
SecondFi's final technical report and compensation framework, when published, will determine whether this incident is contained or whether it accelerates the capital flight that Cardano's metrics already reflect.