Root Cause: Predictable Entropy
Published 6/25/2026, 6:23:48 AM
SecondFi (formerly Yoroi Wallet) lost approximately $2.4 million (16 million ADA) in June 2026 due to a critical vulnerability in its wallet generation software. The breach was caused by a "predictable randomness" flaw in the entropy generation process of version 10.0.3, which allowed attackers to mathematically derive private keys and mnemonic phrases for wallets created during that period [Source: https://finance.yahoo.com/markets/crypto/articles/cardano-project-secondfi-hit-major-091625747.html, https://coinstats.app/news/349de116270f3a4e3cb0e41941671426082eb3078e57c974957d2d4fd5d61b9b_SecondFi-Hack-Puts-Cardano-Users-at-Risk-After-Predictable-Private-Key-Flaw].
Root Cause: Predictable Entropy
The technical failure originated in the entropy generation of SecondFi's native Cardano web wallet software. Instead of utilizing a cryptographically secure pseudorandom number generator (CSPRNG), the software produced private keys using a predictable pattern. This "poisoned" the wallet creation process at the source, meaning any wallet generated with the affected software was inherently compromised from its inception [Source: https://coinstats.app/news/349de116270f3a4e3cb0e41941671426082eb3078e57c974957d2d4fd5d61b9b_SecondFi-Hack-Puts-Cardano-Users-at-Risk-After-Predictable-Private-Key-Flaw].
Exploit Mechanics and Impact
The attack occurred primarily between June 21 and June 22, 2026. Attackers used the randomness flaw to generate batches of valid mnemonic phrases and systematically drained funds, prioritizing larger wallets first.
| Metric | Data Point |
|---|---|
| Confirmed Loss | |
| Estimated Exposure | >129 Million ADA (~$20M+ USD) [Note: not independently confirmed] |
| Affected Wallets | 178 unique stake keys confirmed [Source: https://finance.yahoo.com/markets/crypto/articles/cardano-project-secondfi-hit-major-091625747.html] |
| Software Version | Version 10.0.3 (Released June 7, 2026) |
Security Recommendations
Because the vulnerability exists at the private key level, SecondFi has issued the following warnings:
- Do Not Restore: Users should not attempt to restore seed phrases from affected wallets into other providers (such as Daedalus or Eternl), as the underlying private key is permanently compromised.
- Immediate Migration: Users with funds remaining in wallets created during the affected period must generate entirely new wallets with a different provider and transfer their assets immediately.
While the initial confirmed theft was $2.4 million, security firm SlowMist estimated that the total exposure could exceed $20 million based on an analysis of suspected attacker-controlled wallets [Source: https://www.warpcast.com/happycoinnews/0x97416c13]. Details regarding a formal user compensation or recovery plan have not yet been documented in available reports.