Go to app

Technical Root Cause

Published 6/25/2026, 5:08:10 AM

On June 23, 2026, a critical vulnerability in SecondFi’s (formerly Yoroi) web-based wallet generation software led to the theft of approximately 16 million ADA (valued at $2.4 million). While 16 million ADA was confirmed stolen from 374 unique addresses, security researchers identified that up to 129 million ADA ($20 million) was at risk before emergency rescue measures were implemented [Source: https://slowmist.com/secondfi-investigation/].

Technical Root Cause

The exploit was not a flaw in the Cardano protocol itself, but a defect in SecondFi's proprietary key generation mechanism.

Impact and Loss Metrics

The attack occurred between June 21 and June 22, 2026, with attackers systematically draining larger wallets before moving to smaller balances.

Response and Mitigation

Following the discovery, SecondFi suspended all platform services. To prevent further losses, approximately 129 million ADA was moved to a secure third-party custodian via emergency rescue measures [Source: https://cryptobriefing.com/secondfi-cardano-hack-report/].

Security researchers, including Blink Labs, issued a critical warning: because the key generation process itself was compromised, simply restoring a affected seed phrase into a different wallet provider (like Daedalus or Lace) does not mitigate the risk, as the underlying keys remain fundamentally vulnerable [Source: https://blinklabs.io/security-advisory-secondfi].

Unresolved Technical Details

While the flaw is confirmed as a "predictable private key" issue, specific technical details remain partially undisclosed:

  • Entropy Source: It is not yet publicly confirmed whether the flaw was due to insufficient randomness (entropy) or a specific deviation from Cardano's BIP-39/HD key derivation standards.
  • Recovery Tools: Several "recovery tools" circulating on social media have been flagged by researchers as credential-harvesting scams; users are advised to only use official support channels at support.secondfi.io.

In summary, SecondFi's web-based wallet generation produced predictable keys that allowed attackers to drain 16 million ADA, a loss that would have been significantly higher if not for emergency intervention that secured an additional 129 million ADA.