Root Cause and Technical Vulnerability
Published 6/25/2026, 9:53:16 PM
The SecondFi (formerly Yoroi) exploit on June 21–23, 2026, resulted in a confirmed loss of approximately 16 million ADA (~$2.4 million), though the total exposure of vulnerable funds was estimated at over $20 million [Source: https://cryptorank.io/news/secondfi-yoroi-exploit]. The incident was caused by a critical cryptographic flaw in SecondFi's proprietary wallet-generation software, rather than a vulnerability in the Cardano blockchain itself.
Root Cause and Technical Vulnerability
The exploit originated from a deterministic nonce derivation flaw in the code used to generate private keys [Source: https://cryptorank.io/news/secondfi-yoroi-exploit]. According to analysis by SlowMist founder Cos, this "predictable randomness" allowed attackers to mathematically reconstruct private keys using only public blockchain data [Source: https://intellectia.ai/news/secondfi-yoroi-exploit-analysis].
- The Trigger: The vulnerability is exposed the moment a user signs a transaction. This action leaks sufficient information for an attacker to derive the private key.
- Scope of Impact: The flaw primarily affects wallets created via SecondFi’s web and mobile software. Hardware wallet users (Ledger/Trezor) are safe, as their private keys were never handled by the flawed software.
Loss Details and Fund Recovery
While $2.4 million was stolen and laundered through the Minswap DEX, a significantly larger portion of funds was secured through "white-hat" rescue operations.
| Metric | Value | Status |
|---|---|---|
| Confirmed Stolen | ~16M ADA ($2.4M) | Non-recoverable; laundered via DEXs. |
| Rescued/Secured | ~129M ADA ($19.3M) | Held by an independent third-party custodian. |
| Affected Wallets | 3,072 addresses | 374 drained; others secured by SecondFi. |
| Other Assets | 3,838 token types | Includes ~263M SNEK and ~20M NIGHT tokens. |
Are More Funds at Risk?
Yes, funds remaining in SecondFi-generated wallets are at extreme risk. Because the flaw is at the address-derivation level, the following risks persist:
- Seed Phrase Compromise: Restoring an affected seed phrase into a different wallet (like Eternl or Lace) does not fix the issue. The same compromised addresses will be recreated, and they remain vulnerable to anyone who has already derived the keys [Source: https://intellectia.ai/news/secondfi-yoroi-exploit-analysis].
- Signing Risk: Any attempt to move funds or withdraw staking rewards from an affected address could trigger an automated drain by attackers who are monitoring those addresses.
Current Status and User Action
EMURGO has officially committed to supporting the return of assets to all affected addresses [Source: https://x.com/emurgo_io/status/1942365128378183680]. However, a specific timeline for the distribution of the $19.3M in rescued funds has not yet been announced.
Recommended Actions:
- Do not use the affected wallet for any new transactions.
- Create a brand-new wallet with a fresh seed phrase using a different provider or a hardware wallet.
- Submit a claim via the official incident response portal at
support.secondfi.ioor emailincident-response@secondfi.io.
The Cardano protocol remains fully functional; the exploit was strictly limited to the SecondFi application layer.