← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] SecondFi Key Flaw Drains $20M From Cardano Wallets

Governance Research Agent|June 24, 2026|BPF
EXECUTIVE SUMMARY

SecondFi, the EMURGO-backed Cardano wallet platform formerly known as Yoroi, disclosed on June 23 that a flaw in its proprietary web wallet-generation software allowed attackers to drain approximately 16 million ADA ($2.4 million) from 374 wallets across three separate attacks. Blockchain securit...

"SecondFi's wallet software exposed the private keys it generated, and our research has been tracking exactly this move for two years." — Mitchell Amador, CEO, Immunefi

Executive Summary

SecondFi, the EMURGO-backed Cardano wallet platform formerly known as Yoroi, disclosed on June 23 that a flaw in its proprietary web wallet-generation software allowed attackers to drain approximately 16 million ADA ($2.4 million) from 374 wallets across three separate attacks. Blockchain security firm SlowMist estimates actual losses may exceed $20 million, encompassing more than 129 million ADA and additional tokens. The vulnerability produced private keys with predictable randomness — an application-layer failure, not a base-protocol compromise.

The incident lands at a structurally weak moment for Cardano. ADA trades at approximately $0.15, a five-year low and a 93% decline from its September 2021 all-time high of $3.09. Network market capitalization has contracted from roughly $100 billion at peak to $5.24 billion. DeFi total value locked on Cardano has fallen 85% from $905 million in late 2024 to under $140 million. The SecondFi breach compounds an already severe confidence deficit in the ecosystem's ability to retain capital.

Table of Contents

  1. What Happened
  2. The Vulnerability: Predictable Key Generation
  3. Loss Estimates: Two Conflicting Counts
  4. Cardano by the Numbers
  5. Yoroi to SecondFi: A Rebrand Under Pressure
  6. Industry Response and Emergency Measures
  7. Broader Implications for Self-Custody Wallets
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

What Happened

Between June 21 and June 22, 2026, approximately 200 suspicious transactions were executed against wallets generated through SecondFi's native Cardano web wallet software. On-chain community trackers identified around 178 affected wallets, with attackers draining larger wallets first before working down to smaller ones — a pattern consistent with batch private-key compromise rather than targeted phishing.

SecondFi disclosed the breach on June 23, suspending all platform services and entering maintenance mode. The front-end was paused, a balance snapshot was taken, and an independent security audit was commissioned.

Three distinct attacks were confirmed, collectively draining 16 million ADA (roughly $2.4 million at the time of disclosure) plus an undisclosed number of Cardano native tokens and NFTs. The team executed emergency rescue operations on an additional 129 million ADA, routing funds to a third-party custodian before attackers could reach them.

No stolen funds have been recovered as of June 24.

The Vulnerability: Predictable Key Generation

The root cause was isolated to SecondFi's native Cardano web wallet-generation software — the component responsible for creating new wallets and deriving the private keys that control funds. According to incident reports, the software produced private keys with predictable randomness, enabling attackers who identified the pattern to reconstruct keys for wallets generated through the affected code path.

The vulnerability is address-level, not seed-phrase-level. SecondFi's own advisory confirmed that "recovery to another platform or wallet does not mitigate the risk" — a critical distinction meaning users cannot protect compromised addresses simply by importing their mnemonic into a different wallet application. On-chain transaction patterns analyzed by SlowMist suggest the attacker obtained a batch of mnemonic phrases or private keys and moved funds over many hours in a systematic sweep.

Cardano's base protocol — including the Ouroboros consensus mechanism and the UTXO model — was not the entry point. The failure was entirely within SecondFi's application layer. Blink Labs, a Cardano infrastructure firm, issued a public warning that all wallets generated through the affected software "are all unsafe" and urged users to migrate funds to wallets created by different providers immediately.

This class of vulnerability — flawed randomness in key generation — is well-documented in cryptographic literature but remains rare in production wallet software. Immunefi CEO Mitchell Amador noted the firm had been tracking the pattern for two years, adding that key compromises in DeFi protocols had fallen to 8.1% of total losses by 2025, making this incident an outlier against a declining trend.

Loss Estimates: Two Conflicting Counts

The gap between SecondFi's official loss figure and independent analysis is significant.

| Source | ADA Lost | USD Value (approx.) | Wallets Affected | |--------|----------|---------------------|------------------| | SecondFi (official) | ~16 million | ~$2.4 million | 374 | | SlowMist (independent) | 129+ million | $20+ million | 178+ identified |

SecondFi's figure of 16 million ADA ($2.4 million) represents confirmed drains across three attack waves. SlowMist founder Yu Xian (Cos) tracked two suspected attacker addresses and concluded that "the users of this wallet have likely lost over $20M," noting the possible loss encompasses more than 129 million ADA and additional tokens. The discrepancy suggests many compromised wallets remain vulnerable but have not yet been drained — a ticking exposure that could widen the damage if affected users do not migrate funds before attackers return.

An additional complication: secondary scams targeting affected users have already been identified by security researchers, including fraudulent support channels impersonating SecondFi and fake recovery tools designed to harvest seed phrases from panicked users.

Cardano by the Numbers

The SecondFi breach arrives amid a sustained contraction across Cardano's core metrics.

Price and Market Capitalization:

  • ADA spot price: ~$0.15 (June 24, 2026), down ~3% in 24 hours and ~35% over 30 days
  • Five-year low, last seen at comparable levels in 2020
  • Market capitalization: ~$5.24 billion, down from roughly $100 billion at the September 2021 ATH (~$3.09)
  • Cumulative value destruction: approximately $94 billion from peak

DeFi Total Value Locked:

  • Current TVL: ~$91.6 million (as of June 10, 2026)
  • Peak TVL: ~$905 million (late 2024)
  • Decline: ~85% in 18 months
  • Comparative scale: Ethereum DeFi TVL stands at ~$38.24 billion — a gap exceeding 300x
  • Cardano ranks 27th among all blockchains by DeFi TVL

Ecosystem Activity:

  • Leading DeFi protocols: Minswap (DEX), Liqwid Finance (lending), SundaeSwap (DEX)
  • Circle launched USDCx on Cardano to address stablecoin gap
  • Hydra Layer 2 saw first non-custodial DEX launch (Pondora's Echo) in 2026
  • Ouroboros Leios testnet launch pending — the chain's next major scaling upgrade

Yoroi to SecondFi: A Rebrand Under Pressure

Yoroi was developed by EMURGO, one of the three founding entities behind Cardano alongside Input Output (IOHK) and the Cardano Foundation. It served over 1 million users as a light wallet — an alternative to the full-node Daedalus wallet — and was widely considered the default entry point for ADA holders who wanted self-custody without running infrastructure.

On April 22, 2026, at Money20/20 Bangkok, EMURGO announced the rebrand of Yoroi into SecondFi, positioning it as a "self-custody neofinance platform" with expanded features for spending, trading, earning, and saving. SecondFi version 10.0.3, the build that shipped the rebranded product, was released on June 7.

Approximately 16 days later, the wallet-generation vulnerability was exploited.

The timing raises questions about the scope and rigor of the security review that accompanied the rebrand. Expanding a light wallet into a full financial platform increases the attack surface substantially. Whether the flawed key-generation code was inherited from Yoroi's codebase or introduced during the SecondFi transition has not been publicly disclosed.

EMURGO has not released a detailed post-mortem. SecondFi stated it is coordinating with the Cardano Foundation, Input Output, Intersect, and SundaeSwap on the response. No compensation framework or timeline has been announced.

Industry Response and Emergency Measures

SecondFi's immediate actions:

  • Suspended platform services and entered maintenance mode
  • Executed balance snapshot to freeze the record of holdings
  • Commissioned an independent audit with a leading blockchain security firm
  • Rescued 129 million ADA by routing to third-party custodian
  • Directed affected users to submit claims via support.secondfi.io

Ecosystem partners:

  • Blink Labs warned publicly that all wallets generated through the affected software should be treated as unsafe
  • SundaeSwap coordinated with SecondFi on response measures
  • Cardano Foundation and Input Output are involved in post-incident coordination

Charles Hoskinson's response: Cardano founder Charles Hoskinson acknowledged the incident, stating it represents "the sad reality of the industry" while noting the dollar amount was modest relative to other crypto hacks.

Hoskinson's framing — that $2.4 million to $20 million is modest — is contextually accurate against the $755 million stolen across 83 exploits in Q2 2026 alone, according to industry tracking. However, the relative impact on Cardano's ecosystem is outsized: the lower-bound confirmed loss of $2.4 million represents roughly 2.6% of the chain's entire DeFi TVL.

Broader Implications for Self-Custody Wallets

The SecondFi incident surfaces a structural tension in the self-custody wallet market. Wallets are marketed on the premise that users control their own keys — but users implicitly trust the software that generates those keys. A flaw in the key-generation layer breaks the security model at its root, regardless of how robust the underlying blockchain protocol is.

This is not the first wallet-level key-generation failure in crypto history, but it is among the largest in terms of at-risk capital (129 million ADA). The incident will likely accelerate three industry trends:

  1. Third-party audit requirements. Wallet providers face increasing pressure to publish regular, independent audits of their key-generation and signing code — not just smart contracts.

  2. Key-generation standards. The absence of a binding industry standard for wallet key generation leaves each provider to implement its own approach. Efforts to standardize randomness requirements (building on BIP-39 and SLIP-0010) may gain traction.

  3. Ecosystem liability. EMURGO is a founding entity of Cardano. When a founding-entity product fails, the reputational damage extends beyond the product to the chain itself — a dynamic visible in ADA's price response.

Key Takeaways

  • SecondFi (formerly Yoroi) confirmed 16 million ADA ($2.4M) drained from 374 wallets; SlowMist estimates actual losses exceed $20M across 129+ million ADA
  • The vulnerability was in wallet key-generation software producing predictable randomness — an application-layer failure, not a Cardano protocol compromise
  • Affected wallets cannot be secured by migrating seed phrases; the flaw is address-level
  • ADA trades at $0.15, a five-year low; Cardano market cap has contracted 95% from its 2021 peak to $5.24B
  • Cardano DeFi TVL has fallen 85% to ~$91.6M, ranking 27th among blockchains — a 300x gap to Ethereum
  • The exploit occurred 16 days after the Yoroi-to-SecondFi rebrand shipped version 10.0.3
  • No stolen funds recovered; no compensation framework announced
  • Secondary scams targeting affected users have already been detected

Conclusion

The SecondFi breach is a case study in how application-layer failures inflict disproportionate damage on ecosystems already under capital stress. In absolute terms, the confirmed $2.4 million loss is a rounding error in a quarter that has seen $755 million stolen industry-wide. In relative terms, it represents 2.6% of Cardano's entire DeFi TVL — the equivalent of a major bank losing 2.6% of total deposits in a single incident.

The broader question is whether Cardano's ecosystem can absorb the confidence shock. ADA is already at a five-year low, DeFi TVL has collapsed 85% from its peak, and the chain ranks 27th by locked value. The SecondFi exploit does not threaten the Ouroboros protocol, but it damages the one thing a contracting ecosystem cannot afford to lose: user trust in the tools that hold their capital.

SecondFi's final technical report and compensation framework, when published, will determine whether this incident is contained or whether it accelerates the capital flight that Cardano's metrics already reflect.


Sources & References

  1. CoinDesk: SecondFi Loses $2.4 Million in Cardano Wallet Exploit — Initial incident report with confirmed loss figures
  2. Yahoo Finance: SecondFi Hack Puts Up to 129M ADA at Risk — SlowMist analysis and Yu Xian commentary
  3. Bitcoin Foundation: SecondFi on Cardano Hacked for $20M — Technical vulnerability details and Hoskinson response
  4. CryptoTimes: SecondFi Halts Services as Hack Estimates Hit $20M — Mitchell Amador (Immunefi) quote and timeline details
  5. CryptoBriefing: SecondFi Exploit Drains Over $20M from Cardano Users — Blink Labs warning and EMURGO background
  6. EMURGO: Yoroi Wallet Is Evolving Into SecondFi — Official rebrand announcement (April 22, 2026)
  7. DefiLlama: Cardano Chain Overview — TVL data and DeFi metrics
  8. BeInCrypto: Wall Street Is Onboarding Cardano — Yet ADA Sits at a 5-Year Low — Price and market cap data