SecondFi (Cardano Wallet)
Summary
SecondFi is a Cardano self-custody wallet and neofinance platform operated by EMURGO, rebranded from Yoroi Wallet in April 2026. Between June 21 and 23, 2026, attackers exploited a deterministic nonce-derivation flaw in the platform's wallet generation software, draining approximately 16 million ADA (~$2.4 million) from 374 user wallets. Up to 129 million ADA across 3,072 wallets was placed at risk, with blockchain security firm SlowMist estimating total exposure could exceed $20 million; EMURGO has committed to full user reimbursement through an independently secured restoration fund, though no timeline or audit has been published.
Connected Entities
1 entities · 10 linked investigationsTimeline(6 events)
2026-04-22
EMURGO announces Yoroi Wallet is rebranding to SecondFi at Money20/20 Bangkok, expanding into a self-custody neofinance platform with multichain support and global card payments.
EMURGO official press release2026-06-21
First wave of automated wallet-draining begins at approximately 8:29 PM UTC. Three collector wallets activate simultaneously, draining approximately 12 million ADA from 198 wallets. Stolen tokens are liquidated through Minswap DEX.
Bitquery on-chain forensic investigation2026-06-22
Attacker A conducts a second wave targeting additional SecondFi wallets. Suspicious transaction activity concentrated on June 21-22 per user reports.
Yahoo Finance / 99Bitcoins2026-06-23
Attacker B independently executes a third campaign compromising 203 additional wallets. SecondFi discloses the vulnerability, suspends all platform services, and enters maintenance mode. A second attacker's hub wallet sweeps approximately 135 million ADA from 2,874 wallets, transferring 129,430,001 ADA to a dormant vault in seven transactions. SecondFi triggers emergency containment, routing approximately 129 million ADA to an independent third-party custodian before further exploitation.
Bitquery on-chain forensic investigation; Crypto Briefing2026-06-24
SecondFi and EMURGO publish public disclosures. CoinDesk, BeInCrypto, and multiple crypto news outlets report confirmed losses of approximately 16 million ADA (~$2.4 million) from 374 wallets. SlowMist founder Yu Xian states total exposure including rescued funds may exceed $20 million. SecondFi warns users not to attempt seed phrase migration.
CoinDesk2026-06-25
SecondFi publishes an investigation update. EMURGO commits to full reimbursement for all affected users through a dedicated independently secured restoration fund. Wallet address mapping of 374 affected addresses is stated as complete. Authorities notified; legal action against responsible parties announced.
AMBCrypto; CoinGabbarDecision Log
- hash: GFUX44XrG94PCzQfLqoGsAKr8nKQtREddMFPpQMexyP1
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 6/26/2026, 12:03:58 PM
last updated: 6/26/2026, 12:04:07 PM
avoid.net — verified advice for a post-truth world