TLDR SecondFi, formerly the Yoroi Cardano wallet, suffered a security exploit on June 23 due to a flaw in its wallet key generation software Around 178 walletsTLDR SecondFi, formerly the Yoroi Cardano wallet, suffered a security exploit on June 23 due to a flaw in its wallet key generation software Around 178 wallets

Cardano Wallet SecondFi Hacked: Over $20M at Risk After Private Key Flaw Exposed

2026/06/24 14:58
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

TLDR

  • SecondFi, formerly the Yoroi Cardano wallet, suffered a security exploit on June 23 due to a flaw in its wallet key generation software
  • Around 178 wallets were directly affected, with confirmed losses of approximately 16 million ADA (~$2.4 million)
  • Blockchain security firm SlowMist estimates total potential losses could exceed $20 million, or up to 129 million ADA
  • SecondFi suspended all services and urged its 1 million+ users to move funds to new wallets immediately
  • Secondary scams are now targeting affected users, with fraudsters impersonating SecondFi support channels

SecondFi, the Cardano wallet formerly known as Yoroi, disclosed a security breach on June 23. The vulnerability was found in the platform’s web wallet generation software, which exposed the private keys of certain user wallets.

Around 178 wallets were confirmed as directly affected in the initial assessment. Confirmed losses stand at roughly 16 million ADA, worth approximately $2.4 million, plus additional tokens and NFTs.

Cardano Wallet SecondFi Hacked: Over $20M at Risk After Private Key Flaw Exposed

Blockchain security firm SlowMist put the potential total much higher. Its evaluation estimated losses could exceed $20 million, covering up to 129 million ADA. The gap between confirmed and estimated losses suggests many compromised wallets may not yet have been drained but remain at risk.

SecondFi responded by freezing user balances and switching to maintenance mode. The platform serves over one million users. It warned that any wallet created through its compromised software should be considered at risk.

No compensation timeline has been announced. No detailed audit results have been published.

Background: From Yoroi to SecondFi

SecondFi rebranded from Yoroi in April 2026. Yoroi was developed by Emurgo, one of the three founding organizations behind Cardano. It was a widely used light wallet for ADA holders who wanted self-custody without running a full node.

The rebrand gives the incident added weight. Emurgo’s connection to the Cardano founding team means this is not just a third-party failure. It involves infrastructure tied directly to the ecosystem’s origins.

Security researchers have flagged a second layer of risk following the breach. Scammers are now impersonating SecondFi support channels. They are offering fake recovery tools and attempting to collect credentials from affected users.

Anyone who has ever used SecondFi or the old Yoroi web wallet should act now. The recommended step is to generate new wallet keys using a different provider and transfer all funds immediately.

What Happens Next

A key question is whether Emurgo will step in to compensate affected users. The organization has not indicated plans to do so. Its response in the coming days will be watched closely by the Cardano community.

There is also the broader question of trust. Cardano has built an ecosystem of decentralized finance projects over several years. A breach of this scale, tied to one of its founding members, puts that reputation under pressure.

The platform has not shared a timeline for restoring services or releasing a full security audit. Users remain in a holding pattern with limited official guidance beyond the instruction to move their funds.

The post Cardano Wallet SecondFi Hacked: Over $20M at Risk After Private Key Flaw Exposed appeared first on CoinCentral.

CHZ +28%! Will History Repeat?

CHZ +28%! Will History Repeat?CHZ +28%! Will History Repeat?

0-fee opening long & short. Be ready for any move!

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order