1. What Happened: The Exploit
Published 6/29/2026, 4:39:42 PM
The SecondFi (formerly Yoroi) Cardano exploit, which occurred between June 21–23, 2026, resulted in the theft of approximately 16 million ADA (~$2.4 million) from 374 wallets. As of June 29, 2026, the recovery process is officially on track, with a two-week timeline for asset returns deemed feasible but optimistic.
1. What Happened: The Exploit
The breach was not a failure of the Cardano blockchain but a critical vulnerability in SecondFi's proprietary web wallet generation software.
- Root Cause: A deterministic nonce derivation flaw allowed attackers to reconstruct private keys using only publicly available on-chain data [Source: https://crypto.news/secondfi-cardano-exploit-recovery-status/]. According to the project, this was caused by an unaudited third-party SDK that replaced EMURGO's audited signing code on June 8, 2026 [Note: not independently confirmed].
- The Attack: Three waves of attacks were carried out by two distinct threat actors. Security researchers, including Taylor Monahan, criticized the platform for "rolling their own crypto" rather than using established standards.
- Scope: While $2.4M was confirmed stolen [Source: https://cryptotimes.io/secondfi-exploit-post-mortem/], SlowMist estimates total exposure could exceed $20 million (129M+ ADA) [Source: https://www.tradingview.com/news/99Bitcoins:3191ef6c7094b:0-secondfi-hack-puts-up-to-129m-ada-at-risk-what-it-means-for-cardano/].
2. Current Recovery Status
As of June 29, 2026, SecondFi has moved into the "Building and Testing" phase of its recovery plan.
- Assets Secured: Approximately 129 million ADA has been moved to an independent third-party custodian for emergency protection [Source: https://cryptobriefing.com/secondfi-secures-assets-after-exploit/].
- Milestones Completed: Forensic investigations are finished, and a final balance snapshot of all affected accounts has been taken.
- Next Steps: A wallet checker tool is expected by early next week (approx. July 6), followed by a secure asset migration process [Source: https://crypto.news/secondfi-cardano-exploit-recovery-status/].
3. Can $2.4M be recovered within two weeks?
Assessment: Likely, but with execution risks. The two-week timeline (targeting mid-July 2026) is supported by official statements from EMURGO CEO Phillip Pon, who confirmed a "clear recovery solution" has been identified [Source: https://cointelegraph.com/news/secondfi-recovery-plan-cardano-exploit].
| Factor | Status | Impact on Timeline |
|---|---|---|
| Funding | ✅ Secured | 129M ADA is held by a custodian, far exceeding the $2.4M loss [Source: https://cryptobriefing.com/secondfi-secures-assets-after-exploit/]. |
| Technical | ⚠️ In Progress | 1 week for building + 1 week for testing is a tight window for security software [Source: https://cointelegraph.com/news/secondfi-recovery-plan-cardano-exploit]. |
| Verification | ⏳ Pending | The wallet checker tool must function perfectly to avoid further exploits. |
Conclusion: While the funds are physically secured, the "recovery" (returning them to users) depends on the successful deployment of the new migration tool. A two-week window is the best-case scenario; any bugs found during the testing phase (Week 2) will likely push the timeline into late July.
⚠ Critical Security Warnings
- Keys are Burned: Do NOT restore compromised seed phrases into other wallets. The private keys are effectively public knowledge for the attackers.
- No Independent Action: Do not attempt to move assets or sign new transactions on affected wallets.
- Scam Alert: SecondFi will never ask for your private keys or seed phrases to facilitate recovery. Use only
support.secondfi.io.