SecondFi, the Cardano wallet formerly known as Yoroi, halted services on June 23, 2026 after attackers exploited a flaw in the software that generates new wallets and their private keys. The team confirmed that roughly 16 million ADA, worth about $2.4 million, was drained from 178 user wallets, along with an undisclosed number of tokens and NFTs. Blockchain security firm SlowMist put the figure far higher, estimating that more than 129 million ADA and other assets, worth over $20 million, may have moved through addresses tied to the attacker. SecondFi was built by EMURGO, one of Cardano’s three founding entities, and its Yoroi predecessor served more than one million users.
A self-custody wallet is software that lets users hold their own private keys and control their crypto directly, without a bank or exchange holding the funds.
Key takeaways
- SecondFi (formerly Yoroi) halted operations after a wallet generation flaw exposed users’ private keys.
- The team confirmed about 16 million ADA ($2.4 million) stolen from 178 wallets; SlowMist estimates losses could top $20 million.
- EMURGO, the wallet’s developer, has not committed to reimbursing affected users as of June 24.
- ADA traded near $0.15, down about 3% in 24 hours and close to multi-year lows.
Published: June 24, 2026 16:00 UTC
What triggered the breach
SecondFi traced the theft to its web-based wallet generation software, the component responsible for creating new wallets and the private keys that secure them. According to the team’s disclosure, the defect could expose those keys without the user ever knowing, meaning funds were at risk the moment a wallet was created through the flawed process.
The wallet has deep roots in the Cardano community. EMURGO launched Yoroi years ago as a trusted entry point for ADA holders, and rebranded it to SecondFi in April 2026 while expanding into a broader self-custody platform. That history is why the incident has landed hard: the flaw sat inside infrastructure many holders treated as safe. SecondFi says it has since fixed the vulnerability, though it has not published audit results or a timeline for restoring full service.
The drain echoes a string of recent infrastructure failures in crypto, including the Taiko layer 2 bridge exploit earlier this month and Microsoft’s warning about a USB worm targeting crypto wallets.
Who is affected and what comes next
Anyone who generated a wallet through SecondFi should assume their keys may have been created insecurely. The team and outside researchers advise moving all funds to a new wallet from a different provider, rather than waiting to see whether a given account is drained. The 178 confirmed victims are the floor, not the ceiling, given SlowMist’s wider on-chain estimate.
The fallout has been compounded by opportunists. Fraudulent actors are impersonating SecondFi and pushing fake “recovery tools” designed to harvest seed phrases from panicked users, according to security researchers tracking the incident. EMURGO has not announced compensation, an audit, or a reopening date, leaving affected holders with little recourse beyond migrating their remaining assets.
Markets reacted with a shrug rather than a panic. ADA traded around $0.150 on June 24, down roughly 3% over 24 hours, broadly in line with a weak crypto tape rather than a token-specific collapse. Cardano has slipped out of the top 20 assets by market value this year, and the SecondFi breach adds a fresh trust problem at a moment when the network is already fighting to hold attention.
The technical detail
Key generation is the foundation of wallet security. A wallet derives its private keys from a source of randomness, and if that randomness is predictable or leaks, an attacker can reconstruct the keys and sweep the funds without ever breaching the user’s device. SecondFi’s disclosure points to exactly this class of failure in its web wallet, which is why every wallet created through the tool is suspect, not just the ones already emptied. Unlike a smart contract exploit confined to one protocol, a flawed key generator quietly compromises every user it touched.
Frequently asked questions
How much was actually stolen in the SecondFi hack?
SecondFi confirmed about 16 million ADA, roughly $2.4 million, drained from 178 wallets. SlowMist estimates that up to 129 million ADA and other tokens, worth more than $20 million, may have passed through attacker-linked addresses, so the final tally remains uncertain.
Should I keep using a SecondFi or Yoroi wallet?
Security researchers advise against it. If you created a wallet through SecondFi or Yoroi, the keys may have been generated insecurely. The recommended step is to move all funds to a new wallet from a different provider and avoid any “recovery tools” claiming to fix the issue.
Will affected users be reimbursed?
As of June 24, 2026, EMURGO has not committed to compensating victims. The company has not published audit findings or a recovery plan, so there is no confirmed reimbursement process for users who lost funds.
Sources: BeInCrypto, Crypto Briefing, Protos, FXStreet.








