What to Know
- 16 million ADA (~$2.4 million) was drained from 374 addresses in the SecondFi exploit
- SecondFi secured 129 million ADA and is moving funds to an independent third-party custodian
- The flaw was in SecondFi’s wallet key generation software, not in the Cardano blockchain itself
- SecondFi rebranded from Yoroi wallet in April 2026 and is unaffiliated with IOG
The SecondFi Cardano wallet exploit has been traced to a flaw at the address level. The platform confirmed on Wednesday that attackers drained roughly 16 million ADA, worth about $2.4 million, from 374 user addresses. SecondFi also said it secured 129 million ADA through emergency measures, and those funds are now moving to an independent third-party custodian while affected users await verification.
What Caused the SecondFi Cardano Wallet Exploit?
The root cause was a vulnerability in the software that SecondFi used to generate wallet addresses. According to SecondFi, the flaw affects users at the point when they sign transactions. The wallet generation code exposed private keys, which gave attackers direct access to user funds.
Mitchell Amador, CEO of blockchain security firm Immunefi, explained what went wrong. He said that while the SecondFi Cardano wallet exploit $2.4 million left the underlying blockchain untouched, the key generation code is the part that rarely gets the same scrutiny as a smart contract audit. “SecondFi’s wallet software exposed the private keys it generated,” Amador told reporters, adding that attackers are increasingly targeting infrastructure that creates or stores crypto keys rather than the blockchain protocols themselves.
The breach is a reminder that self-custodial wallets carry their own risks. A secure blockchain does not protect users if the software sitting in front of it mishandles private keys. Amador’s point about auditing gaps is worth taking seriously. Key generation code is invisible to most users and often gets skipped in routine security reviews.
SecondFi’s wallet software exposed the private keys it generated. Attackers have increasingly shifted focus toward infrastructure that creates or stores crypto keys rather than blockchain protocols.
SecondFi Secures 129 Million ADA After Emergency Response
Once SecondFi identified the root cause, it triggered emergency measures. The platform said it secured roughly SecondFi 129 million ADA secured third-party custodian and is now transferring those funds to an independent third-party custodian. Affected users will get access to the secured ADA after a verification process is completed.
The platform also stated that recovery to another Cardano wallet does not reduce the risk for compromised addresses. SecondFi told users not to restore their recovery phrases into any new Cardano wallet. That guidance clashed with advice from some community members, who urged users to migrate funds to freshly created addresses. SecondFi did not publicly explain the technical reason for the conflicting recommendations.
The gap between SecondFi’s guidance and community advice created confusion. Users were left choosing between the platform’s official warning and community suggestions that contradicted it. That kind of contradictory messaging after a major exploit is a problem. It slows down user response and can lead to more losses.
SecondFi said it is now working with Cardano ecosystem platforms and independent blockchain investigators to address the full scope of the incident. No comprehensive post-mortem had been published as of the time of reporting. The platform has issued multiple statements confirming the breach but has not yet released a full technical breakdown.
Charles Hoskinson and IOG Distance Themselves From SecondFi
Cardano founder Charles Hoskinson was clear about one thing: IOG did not build SecondFi. Hoskinson said in a statement that SecondFi is not an Input Output Global product and that IOG has no ownership, control, or business relationship with the wallet.
In a video posted to X on Tuesday, Hoskinson said IOG “is not Emurgo” and cannot speak on Emurgo’s behalf regarding the exploit. “We didn’t write the code and we’re not connected to it,” he said. Despite that distance, Hoskinson confirmed that IOG’s incident response team had been in contact with SecondFi since Monday and that the platform has requested an independent security audit.
Emurgo, the organization that built the original Yoroi wallet, describes itself as the for-profit arm of Cardano. Hoskinson was explicit that IOG has no influence over Emurgo. The distinction matters for users trying to understand accountability after the exploit.
We didn’t write the code and we’re not connected to it.
SecondFi Is the Rebranded Yoroi Wallet. Here Is the History.
SecondFi is not a new name in the Cardano space. It is the rebranded version of Yoroi wallet, one of the oldest Cardano wallets in existence. The Yoroi wallet SecondFi rebrand April 2026 happened in April 2026, just weeks before this exploit was reported.
Yoroi was originally developed by Emurgo. It was launched as the first open-source light wallet built specifically for the Cardano blockchain. The wallet has had a long user base, which is part of why the exploit affected so many addresses. Users who had held Yoroi accounts through the rebrand had their funds exposed.
The timing of the rebrand raises questions. A major wallet migration to a new brand is a high-risk period for any platform. Code changes, new wallet generation software, and updated infrastructure all increase the attack surface. Whether the rebrand process introduced the vulnerability or whether it pre-existed the rebrand is something the post-mortem will need to address.
The exploit also puts a spotlight on how self-custodial wallets communicate security incidents. SecondFi’s handling of the event has been fragmented. Multiple statements, contradictory user guidance, and no published post-mortem is a rough combination when hundreds of users are trying to decide what to do with their funds.
What Does the Cardano Ecosystem Do Now?
The broader Cardano ecosystem is watching closely. This exploit did not target the blockchain itself. The Cardano network functioned normally throughout the incident. But a wallet exploit of this size damages user confidence regardless of where the flaw originated.
Amador’s broader observation deserves attention. He said attackers have shifted focus from blockchain protocols to the software that manages and generates keys. That is a harder problem to solve than fixing smart contract bugs. Key generation code lives in wallets, custodians, hardware devices, and browser extensions. Most of it has never been formally audited.
For Cardano users still holding funds in any wallet that touches the old Yoroi codebase, the safest move right now is to wait for SecondFi’s official post-mortem before taking action. Moving funds hastily to a new wallet, especially using an existing recovery phrase, could expose users to the same vulnerability that was already exploited.
The $2.4 million loss figure covers only the 374 addresses that were directly drained. The 129 million ADA that SecondFi secured represents a much larger pool of user funds that may have been at risk. The full extent of the exposure will not be clear until a proper audit is complete.
SecondFi’s path forward involves two things. First, a transparent technical post-mortem that explains exactly how private keys were exposed and what the platform changed to fix it. Second, a clear and consistent recovery process for affected users. Right now, neither of those is fully in place.

Frequently Asked Questions
What is the SecondFi Cardano wallet exploit?
The SecondFi Cardano wallet exploit was a security breach caused by a flaw in SecondFi’s wallet key generation software. Attackers exploited exposed private keys to drain approximately 16 million ADA, worth around $2.4 million, from 374 user addresses. The Cardano blockchain itself was not compromised.
How much ADA was stolen in the SecondFi exploit?
Attackers drained approximately 16 million ADA, valued at around $2.4 million at the time of the exploit, across 374 affected addresses. SecondFi separately secured 129 million ADA through emergency measures and is holding those funds in a third-party custodian for affected users pending verification.
Is Cardano or IOG responsible for the SecondFi exploit?
No. Cardano founder Charles Hoskinson confirmed that IOG has no ownership, control, or business relationship with SecondFi. The Cardano blockchain itself was not compromised. The vulnerability was in SecondFi’s own wallet generation software, which was built by Emurgo, the for-profit arm of the Cardano ecosystem.
What should SecondFi users do after the exploit?
SecondFi advised users not to restore their recovery phrases into new Cardano wallets, as that does not eliminate the risk from compromised addresses. Users should wait for SecondFi’s official post-mortem and follow only official platform guidance rather than informal community advice until a verified recovery process is published.
This article is for informational purposes only and does not constitute investment advice. Every investment and trading decision involves risk. Readers should conduct their own research before making any financial decisions.



































374 addresses hit but only 16M ADA drained averages out to small per-wallet balances, so this was probably a wallet-software user base not whales. address-level key gen flaw is the scary part though, was it deterministic derivation gone wrong or entropy collapse?
another self-custody wallet shipping prod code without a third party audit of the key derivation path. we keep learning the same lesson every cycle and pretending its new.
reminds me of the Profanity vanity address bug in 2022, same root cause class. predictable entropy in address generation has been a known footgun for years and teams still ship it.
how did SecondFi disclose this to affected users, on chain message or just a tweet?