Skip to main content
Sign in

SecondFi (Cardano Wallet)

avoid.net/secondfi-cardano-wallet28/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]
anchored·45awDp…FGQ8

Summary

SecondFi is a Cardano self-custody wallet and neofinance platform operated by EMURGO, rebranded from Yoroi Wallet in April 2026. Between June 21 and 23, 2026, attackers exploited a deterministic nonce-derivation flaw in the platform's wallet generation software, draining approximately 16 million ADA (~$2.4 million) from 374 user wallets. Up to 129 million ADA across 3,072 wallets was placed at risk, with blockchain security firm SlowMist estimating total exposure could exceed $20 million; EMURGO has committed to full user reimbursement through an independently secured restoration fund, though no timeline or audit has been published.

Have evidence about SecondFi (Cardano Wallet)?

Timeline(6 events)

2026-04-22

EMURGO announces Yoroi Wallet is rebranding to SecondFi at Money20/20 Bangkok, expanding into a self-custody neofinance platform with multichain support and global card payments.

EMURGO official press release

2026-06-21

First wave of automated wallet-draining begins at approximately 8:29 PM UTC. Three collector wallets activate simultaneously, draining approximately 12 million ADA from 198 wallets. Stolen tokens are liquidated through Minswap DEX.

Bitquery on-chain forensic investigation

2026-06-22

Attacker A conducts a second wave targeting additional SecondFi wallets. Suspicious transaction activity concentrated on June 21-22 per user reports.

Yahoo Finance / 99Bitcoins

2026-06-23

Attacker B independently executes a third campaign compromising 203 additional wallets. SecondFi discloses the vulnerability, suspends all platform services, and enters maintenance mode. A second attacker's hub wallet sweeps approximately 135 million ADA from 2,874 wallets, transferring 129,430,001 ADA to a dormant vault in seven transactions. SecondFi triggers emergency containment, routing approximately 129 million ADA to an independent third-party custodian before further exploitation.

Bitquery on-chain forensic investigation; Crypto Briefing

2026-06-24

SecondFi and EMURGO publish public disclosures. CoinDesk, BeInCrypto, and multiple crypto news outlets report confirmed losses of approximately 16 million ADA (~$2.4 million) from 374 wallets. SlowMist founder Yu Xian states total exposure including rescued funds may exceed $20 million. SecondFi warns users not to attempt seed phrase migration.

CoinDesk

2026-06-25

SecondFi publishes an investigation update. EMURGO commits to full reimbursement for all affected users through a dedicated independently secured restoration fund. Wallet address mapping of 374 affected addresses is stated as complete. Authorities notified; legal action against responsible parties announced.

AMBCrypto; CoinGabbar
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.

model: claude-sonnet-4-6

generated: 6/26/2026, 12:03:58 PM

last updated: 6/26/2026, 12:04:07 PM

avoid.net — verified advice for a post-truth world