SecondFi Wallet Key-Generation Exploit
A predictable-randomness flaw in SecondFi's Cardano wallet-generation software let attackers drain about $2.4M in ADA from 178 wallets, with up to $20M more potentially at risk.
- Date
- Chain(s)
- Status
- Funds Stolen
On June 23, 2026, SecondFi — the Cardano self-custody wallet formerly known as Yoroi — disclosed that a flaw in its own wallet-generation software had let attackers drain roughly $2.4 million in ADA from 178 user wallets, with security firm SlowMist warning that as much as 129 million ADA (over $20 million) could ultimately be at risk. Cardano's base protocol was not compromised; the weakness lived entirely in SecondFi's client software.
What happened
The root cause was predictable randomness in the software that creates new wallets and their private keys. Because the key-generation routine did not draw from sufficient entropy, the resulting private keys were guessable — meaning every wallet produced by that iteration of the software is potentially compromised, including accounts that have not yet been drained. Attackers swept ADA, native tokens and NFTs from affected accounts; on-chain trackers identified about 178 drained wallets, with suspicious activity concentrated in the June 21–22 window before the public disclosure on June 23. The confirmed loss stands near $2.4 million, but SecondFi has cautioned that the official figure is a floor, not a ceiling, pending an independent review.
Aftermath
SecondFi immediately suspended services and entered maintenance mode, took a snapshot of user balances to freeze a record of holdings, and urged users to move funds out of any wallet generated by the affected software. The team said it is finalizing a technical review with a leading blockchain security firm and is coordinating with major Cardano stakeholders — Input Output Global (IOG), the Cardano Foundation, IntersectMBO and SundaeSwap — to manage the fallout. No reimbursement timeline has been announced, and no funds had been recovered at the time of disclosure.
Update (June 27, 2026): Parent firm EMURGO outlined a recovery plan, with CEO Phillip Pon saying the team had identified a solution tailored to existing wallet states — roughly one week to build the technical recovery mechanism and another week of testing and security validation before assets begin returning to affected users. Separately, on-chain trackers flagged a movement of about 129 million ADA that SecondFi framed as an emergency "white-hat" rescue, routed to "an independent, qualified third-party custodian" and held for the benefit of affected addresses, with an external accounting firm engaged to verify the holdings. The arrangement drew scrutiny, with some community members questioning whether EMURGO knew the white-hat's identity — which EMURGO denied. As of the announcement, no stolen funds had been returned to users.
Update (July 2026): EMURGO confirmed that SecondFi will not reopen — even once audits are complete, the wallet will not resume normal operations, and the team's role has narrowed to a recovery effort, backed by a separately secured restitution fund set up to reimburse affected holders through a claims process, though no firm date was given for returning the stolen ADA. EMURGO also began winding down its wider Cardano wallet operations: its sibling multichain wallet Ctrl Wallet — brought under the EMURGO umbrella on April 29, 2026, with its technology folding into SecondFi — disclosed its own Cardano security incident in the same June window and, unable to land a satisfactory fix, announced it will permanently shut down on August 3, 2026. Ctrl Wallet's mobile apps and browser extensions were pulled from the Apple App Store, Google Play and extension stores on July 7, with users urged to export recovery phrases and move funds before the deadline, after which the app enters export-only mode. The fallout also reached EMURGO's governance standing: on July 14 it handed the Cardano Token2049 event to the Cardano Foundation to focus on recovery, and it stepped down from its seat in the Pentad governance coalition — the first of the group's five members to exit.
Why it matters
Weak key generation is one of the most catastrophic failure modes in crypto because it breaks every wallet at once, not just one victim. The incident echoes the Wintermute Profanity exploit, where a predictable vanity-address generator let an attacker recompute a private key and steal $160M, and it lands the same month as the key-handling failure at Humanity Protocol. For a widely used consumer wallet, a single flawed entropy source converts the convenience of self-custody into a systemic liability — and underscores why deterministic, well-audited randomness is non-negotiable in any tool that mints private keys.
Sources & on-chain evidence
- [01]coindesk.comhttps://www.coindesk.com/business/2026/06/24/secondfi-loses-usd2-4-million-in-cardano-wallet-exploit-with-up-to-usd20-million-at-risk
- [02]cryptobriefing.comhttps://cryptobriefing.com/secondfi-exploit-drains-cardano-users/
- [03]cryptobriefing.comhttps://cryptobriefing.com/secondfi-wallet-vulnerability-cardano-drain/
- [04]en.cryptonomist.chhttps://en.cryptonomist.ch/2026/06/24/secondfi-cardano-exploit-losses/
- [05]cryptotimes.iohttps://www.cryptotimes.io/2026/06/24/cardano-project-secondfi-halts-services-as-hack-estimates-hit-20m/
- [06]crypto.newshttps://crypto.news/secondfi-keeps-two-week-recovery-plan-after-2-4m-cardano-wallet-exploit/
- [07]cryptonews.comhttps://cryptonews.com/news/ada-price-secondfi-wallet-exploit-white-hat-hacker/
- [08]crowdfundinsider.comhttps://www.crowdfundinsider.com/2026/06/288226-secondfi-outlines-recovery-plan-after-2-4-million-cardano-wallet-breach/
- [09]crypto.newshttps://crypto.news/secondfi-wont-reopen-after-cardano-wallet-breach/
- [10]cryptotimes.iohttps://www.cryptotimes.io/2026/07/06/emurgo-winds-down-secondfi-for-good-as-cardano-hack-recovery-drags-on/
- [11]crypto.newshttps://crypto.news/ctrl-wallet-shuts-down-after-exploit-urges-move-funds/
- [12]cointelegraph.comhttps://cointelegraph.com/news/ctrl-wallet-shutdown-security-exploit
- [13]cryptotimes.iohttps://www.cryptotimes.io/2026/07/07/ctrl-wallet-to-fully-shut-down-by-august-3-deletes-mobile-apps-early/
- [14]en.cryptonomist.chhttps://en.cryptonomist.ch/2026/07/08/emurgo-cardano-pentad-withdrawal/