A vulnerability in SecondFi's proprietary wallet generation software allowed three external attackers to drain approximately 16 million ADA (about $2.4 million) from 374 user addresses between June 21 and June 23, 2026.

Create a landscape editorial hero image for this Studio Global article: Search & fact-check with cited sources for What happened in the SecondFi Cardano wallet exploit that drained about 16 million ADA from 374 a. Article summary: Here is a comprehensive, source-backed summary of the SecondFi Cardano wallet exploit.. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence
Between June 21 and June 23, 2026, a critical vulnerability in SecondFi — the Cardano wallet formerly known as Yoroi, built by EMURGO — allowed three external attackers to drain approximately 16 million ADA (worth about $2.4 million at the time) from 374 user addresses across three successive attack waves . Tokens and NFTs were also taken from affected wallets
.
The exploit was discovered after users reported unauthorized transfers from wallets that had been created through the SecondFi web interface. The platform was placed into secure maintenance mode on June 23 while investigators began analyzing the incident .
The vulnerability was traced to SecondFi's proprietary web wallet generation/key generation software — specifically its Cardano address-generation logic at the private key level . SecondFi described the issue as an "address-level" flaw in its wallet creation code that exposed users' private keys
.
According to SecondFi's investigation, the attack stemmed from a deterministic nonce derivation flaw in its software signer. This allowed attackers to mathematically reconstruct private keys from publicly available blockchain data after affected addresses signed transactions .
Crucially, the compromise occurred within SecondFi's application layer, not in the Cardano protocol, the open-source wallet infrastructure, or the core cryptography . SecondFi confirmed that the vulnerability was confined to its own software, and no underlying Cardano component was affected
.
Early in the incident, blockchain security firm SlowMist estimated total losses could exceed $20 million, and reports warned that up to 129 million ADA sitting in vulnerable wallets was at risk .
SecondFi's emergency response was aggressive: The team identified the root cause, deployed patches to unaffected wallets, and — most critically — in a "fourth wave" of transactions, front-ran the attackers and moved 129 million ADA from still-vulnerable wallets to an independent third-party custodian, securing those funds before they could be stolen . That amount was not "drained" — it was rescued
.
EMURGO's response: EMURGO, one of Cardano's three founding entities and SecondFi's developer, funded an Asset Recovery Wallet specifically to return assets to users whose wallets were compromised . However, reports indicate EMURGO has not committed to fully compensating all affected users beyond returning rescued/recoverable funds
. The official FAQ states that assets drained by attackers are "protected and accessible" and that EMURGO is in discussion with IntersectMBO on the custody mechanism
.
In multiple statements on June 23–25, 2026, Charles Hoskinson emphasized that the Cardano blockchain itself was not hacked . His reasoning centered on three points:
Blockchain security experts and multiple reports independently confirmed this distinction: the Cardano network continued operating normally throughout .
SecondFi issued an urgent warning that affected users should NOT restore their recovery phrases into another Cardano wallet . The compromise is at the private key level — restoring the same phrase into a different wallet does not fix the exposure; attackers can still access those addresses
.
Instead, all users were advised to create entirely new wallets with new recovery phrases and migrate funds immediately .
SecondFi created a complete balance snapshot of affected user funds and continued recording multiple rounds of snapshots during the incident response . On June 26, the team completed a final balance snapshot to serve as the basis for refund processing
.
Compensation details:
SecondFi warned that fraudulent actors were impersonating SecondFi to distribute fake recovery/scam tools . Users were instructed to use only official channels and to remember that no legitimate recovery tool ever requires sharing seed phrases
.
The team reiterated that no legitimate recovery tool requires users to share their seed phrases .
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
A vulnerability in SecondFi's proprietary wallet generation software allowed three external attackers to drain approximately 16 million ADA (about $2.4 million) from 374 user addresses between June 21 and June 23, 2026.