SecondFi, the Cardano based self-custody wallet and neofinance platform formerly known as Yoroi, disclosed a security vulnerability in its web wallet generationSecondFi, the Cardano based self-custody wallet and neofinance platform formerly known as Yoroi, disclosed a security vulnerability in its web wallet generation

SecondFi Wallet Vulnerability Drains Millions in Cardano Assets

2026/06/24 15:12
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

SecondFi, the Cardano based self-custody wallet and neofinance platform formerly known as Yoroi, disclosed a security vulnerability in its web wallet generation software that led to the unauthorized draining of roughly 16 million ADA, worth approximately 2.4 million dollars, from a small number of user wallets. The project placed its platform into maintenance mode on June 23 after detecting the issue, pausing front end interactions to contain the problem.

According to SecondFi’s official statement, the root cause was isolated to its native Cardano web wallet generation software. The team has completed on chain analysis and is working with a leading blockchain security firm for an independent technical review. It has also taken a snapshot of user balances and is collaborating with entities including Input Output (IOG), the Cardano Foundation, and other Cardano ecosystem participants to monitor fund flows.

Security researcher Cos, co founder of SlowMist, analyzed on chain activity and estimated that total losses could exceed 20 million dollars, including over 129 million ADA and other tokens. He identified specific addresses believed to be controlled by the attacker, including addr1q8g8…ss7vuz99 and addr1qxd3…shwxpl3. Cos noted that drains appeared to continue over an extended period.

slowmist co founderslowmist co founder

SecondFi has stated that the issue affected only a limited number of wallets created through its web interface and has urged users to remain vigilant against impersonators and scams during the maintenance period. Official support is available only through their ticket system.

SecondFi, developed by EMURGO, a founding entity of the Cardano blockchain, positions itself as a self custody platform for spending, trading, earning, and saving on Cardano. This marks a significant security incident for the wallet, which evolved from the long standing Yoroi wallet.

The incident comes at a time when the Cardano ecosystem is facing challenges. The network has recently been grappling with governance disputes and questions surrounding Charles Hoskinson’s handling of a 1,096 BTC treasury matter, adding to broader concerns among parts of the community over transparency and decision making within the ecosystem.

The community has also been divided over a proposed $52 million research funding initiative, a debate that has further highlighted disagreements over how Cardano’s resources should be allocated and how the ecosystem should prioritize future development. The network continues to see low DeFi activity with Total Value Locked (TVL) at around $85.76 million and lower trading volumes compared to leading blockchains.

The platform remains in maintenance mode while its engineering team works to restore functionality. Further updates on compensation for affected users and detailed investigation findings are expected in the coming days. The exploit also adds to a growing list of wallet security incidents across the crypto industry, following other high profile breaches that exposed weaknesses in wallet infrastructure and internal security controls.

SecondFi has not disclosed additional details on the exact number of impacted users or full recovery plans. Users with funds on the platform are advised to monitor official channels for further instructions.

Market Opportunity
Based Logo
Based Price(BASED)
$0.09232
$0.09232$0.09232
-2.22%
USD
Based (BASED) Live Price Chart

CHZ +28%! Will History Repeat?

CHZ +28%! Will History Repeat?CHZ +28%! Will History Repeat?

0-fee opening long & short. Be ready for any move!

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order