Technical Root Cause
Published 6/25/2026, 5:08:10 AM
On June 23, 2026, a critical vulnerability in SecondFi’s (formerly Yoroi) web-based wallet generation software led to the theft of approximately 16 million ADA (valued at $2.4 million). While 16 million ADA was confirmed stolen from 374 unique addresses, security researchers identified that up to 129 million ADA ($20 million) was at risk before emergency rescue measures were implemented [Source: https://slowmist.com/secondfi-investigation/].
Technical Root Cause
The exploit was not a flaw in the Cardano protocol itself, but a defect in SecondFi's proprietary key generation mechanism.
- Predictable Private Keys: The vulnerability stemmed from a "predictable private key flaw" in the web interface's wallet-generation software [Source: https://cryptobriefing.com/secondfi-cardano-hack-june-2026/]. This allowed attackers to derive private keys or mnemonic phrases that should have been cryptographically secure.
- Activation Mechanism: The vulnerability was reportedly triggered at the address level when a user signed a transaction, which exposed the underlying cryptographic keys to the exploit [Source: https://blinklabs.io/security-advisory-secondfi].
- Scope of Impact: The flaw was strictly limited to wallets generated through the SecondFi/Yoroi web interface. Hardware wallets and wallets created through other Cardano providers remained unaffected [Source: https://www.coindesk.com/tech/2026/06/24/secondfi-16m-ada-exploit-what-we-know/].
Impact and Loss Metrics
The attack occurred between June 21 and June 22, 2026, with attackers systematically draining larger wallets before moving to smaller balances.
| Metric | Value | Source |
|---|---|---|
| Confirmed ADA Stolen | ~16 million ADA | Source: https://www.coindesk.com/tech/2026/06/23/secondfi-cardano-16m-ada-exploit/ |
| Potential ADA at Risk | ~129 million ADA | Source: https://slowmist.com/secondfi-investigation/ |
| Estimated USD Loss | ~$2.4 million | Source: https://cryptobriefing.com/secondfi-cardano-hack-report/ |
| Wallets Drained | 374 addresses | Source: https://www.coindesk.com/tech/2026/06/23/secondfi-cardano-16m-ada-exploit/ |
| ADA Price Impact | -3.6% (24h) | Source: https://cryptobriefing.com/secondfi-cardano-hack-june-2026/ |
Response and Mitigation
Following the discovery, SecondFi suspended all platform services. To prevent further losses, approximately 129 million ADA was moved to a secure third-party custodian via emergency rescue measures [Source: https://cryptobriefing.com/secondfi-cardano-hack-report/].
Security researchers, including Blink Labs, issued a critical warning: because the key generation process itself was compromised, simply restoring a affected seed phrase into a different wallet provider (like Daedalus or Lace) does not mitigate the risk, as the underlying keys remain fundamentally vulnerable [Source: https://blinklabs.io/security-advisory-secondfi].
Unresolved Technical Details
While the flaw is confirmed as a "predictable private key" issue, specific technical details remain partially undisclosed:
- Entropy Source: It is not yet publicly confirmed whether the flaw was due to insufficient randomness (entropy) or a specific deviation from Cardano's BIP-39/HD key derivation standards.
- Recovery Tools: Several "recovery tools" circulating on social media have been flagged by researchers as credential-harvesting scams; users are advised to only use official support channels at
support.secondfi.io.
In summary, SecondFi's web-based wallet generation produced predictable keys that allowed attackers to drain 16 million ADA, a loss that would have been significantly higher if not for emergency intervention that secured an additional 129 million ADA.