Home / News / Altcoins / SecondFi Cardano Wallet Exploit Traced to Address-Level Bug

Written By

SecondFi Cardano Wallet Exploit Traced to Address-Level Bug

SecondFi Cardano Wallet Exploit Traced to Address-Level Bug
SecondFi Cardano Wallet Exploit Traced to Address-Level Bug

What to Know

  • 16 million ADA (~$2.4 million) was drained from 374 addresses in the SecondFi exploit
  • SecondFi secured 129 million ADA and is moving funds to an independent third-party custodian
  • The flaw was in SecondFi’s wallet key generation software, not in the Cardano blockchain itself
  • SecondFi rebranded from Yoroi wallet in April 2026 and is unaffiliated with IOG

The SecondFi Cardano wallet exploit has been traced to a flaw at the address level. The platform confirmed on Wednesday that attackers drained roughly 16 million ADA, worth about $2.4 million, from 374 user addresses. SecondFi also said it secured 129 million ADA through emergency measures, and those funds are now moving to an independent third-party custodian while affected users await verification.

What Caused the SecondFi Cardano Wallet Exploit?

The root cause was a vulnerability in the software that SecondFi used to generate wallet addresses. According to SecondFi, the flaw affects users at the point when they sign transactions. The wallet generation code exposed private keys, which gave attackers direct access to user funds.

Mitchell Amador, CEO of blockchain security firm Immunefi, explained what went wrong. He said that while the SecondFi Cardano wallet exploit $2.4 million left the underlying blockchain untouched, the key generation code is the part that rarely gets the same scrutiny as a smart contract audit. “SecondFi’s wallet software exposed the private keys it generated,” Amador told reporters, adding that attackers are increasingly targeting infrastructure that creates or stores crypto keys rather than the blockchain protocols themselves.

The breach is a reminder that self-custodial wallets carry their own risks. A secure blockchain does not protect users if the software sitting in front of it mishandles private keys. Amador’s point about auditing gaps is worth taking seriously. Key generation code is invisible to most users and often gets skipped in routine security reviews.

SecondFi’s wallet software exposed the private keys it generated. Attackers have increasingly shifted focus toward infrastructure that creates or stores crypto keys rather than blockchain protocols.

— Mitchell Amador, CEO, Immunefi

SecondFi Secures 129 Million ADA After Emergency Response

Once SecondFi identified the root cause, it triggered emergency measures. The platform said it secured roughly SecondFi 129 million ADA secured third-party custodian and is now transferring those funds to an independent third-party custodian. Affected users will get access to the secured ADA after a verification process is completed.

The platform also stated that recovery to another Cardano wallet does not reduce the risk for compromised addresses. SecondFi told users not to restore their recovery phrases into any new Cardano wallet. That guidance clashed with advice from some community members, who urged users to migrate funds to freshly created addresses. SecondFi did not publicly explain the technical reason for the conflicting recommendations.

The gap between SecondFi’s guidance and community advice created confusion. Users were left choosing between the platform’s official warning and community suggestions that contradicted it. That kind of contradictory messaging after a major exploit is a problem. It slows down user response and can lead to more losses.

SecondFi said it is now working with Cardano ecosystem platforms and independent blockchain investigators to address the full scope of the incident. No comprehensive post-mortem had been published as of the time of reporting. The platform has issued multiple statements confirming the breach but has not yet released a full technical breakdown.

Charles Hoskinson and IOG Distance Themselves From SecondFi

Cardano founder Charles Hoskinson was clear about one thing: IOG did not build SecondFi. Hoskinson said in a statement that SecondFi is not an Input Output Global product and that IOG has no ownership, control, or business relationship with the wallet.

In a video posted to X on Tuesday, Hoskinson said IOG “is not Emurgo” and cannot speak on Emurgo’s behalf regarding the exploit. “We didn’t write the code and we’re not connected to it,” he said. Despite that distance, Hoskinson confirmed that IOG’s incident response team had been in contact with SecondFi since Monday and that the platform has requested an independent security audit.

Emurgo, the organization that built the original Yoroi wallet, describes itself as the for-profit arm of Cardano. Hoskinson was explicit that IOG has no influence over Emurgo. The distinction matters for users trying to understand accountability after the exploit.

We didn’t write the code and we’re not connected to it.

— Charles Hoskinson, Cardano Founder

SecondFi Is the Rebranded Yoroi Wallet. Here Is the History.

SecondFi is not a new name in the Cardano space. It is the rebranded version of Yoroi wallet, one of the oldest Cardano wallets in existence. The Yoroi wallet SecondFi rebrand April 2026 happened in April 2026, just weeks before this exploit was reported.

Yoroi was originally developed by Emurgo. It was launched as the first open-source light wallet built specifically for the Cardano blockchain. The wallet has had a long user base, which is part of why the exploit affected so many addresses. Users who had held Yoroi accounts through the rebrand had their funds exposed.

The timing of the rebrand raises questions. A major wallet migration to a new brand is a high-risk period for any platform. Code changes, new wallet generation software, and updated infrastructure all increase the attack surface. Whether the rebrand process introduced the vulnerability or whether it pre-existed the rebrand is something the post-mortem will need to address.

The exploit also puts a spotlight on how self-custodial wallets communicate security incidents. SecondFi’s handling of the event has been fragmented. Multiple statements, contradictory user guidance, and no published post-mortem is a rough combination when hundreds of users are trying to decide what to do with their funds.

What Does the Cardano Ecosystem Do Now?

The broader Cardano ecosystem is watching closely. This exploit did not target the blockchain itself. The Cardano network functioned normally throughout the incident. But a wallet exploit of this size damages user confidence regardless of where the flaw originated.

Amador’s broader observation deserves attention. He said attackers have shifted focus from blockchain protocols to the software that manages and generates keys. That is a harder problem to solve than fixing smart contract bugs. Key generation code lives in wallets, custodians, hardware devices, and browser extensions. Most of it has never been formally audited.

For Cardano users still holding funds in any wallet that touches the old Yoroi codebase, the safest move right now is to wait for SecondFi’s official post-mortem before taking action. Moving funds hastily to a new wallet, especially using an existing recovery phrase, could expose users to the same vulnerability that was already exploited.

The $2.4 million loss figure covers only the 374 addresses that were directly drained. The 129 million ADA that SecondFi secured represents a much larger pool of user funds that may have been at risk. The full extent of the exposure will not be clear until a proper audit is complete.

SecondFi’s path forward involves two things. First, a transparent technical post-mortem that explains exactly how private keys were exposed and what the platform changed to fix it. Second, a clear and consistent recovery process for affected users. Right now, neither of those is fully in place.

ADA price and market data
Source: CoinMarketCap

Frequently Asked Questions

What is the SecondFi Cardano wallet exploit?

The SecondFi Cardano wallet exploit was a security breach caused by a flaw in SecondFi’s wallet key generation software. Attackers exploited exposed private keys to drain approximately 16 million ADA, worth around $2.4 million, from 374 user addresses. The Cardano blockchain itself was not compromised.

How much ADA was stolen in the SecondFi exploit?

Attackers drained approximately 16 million ADA, valued at around $2.4 million at the time of the exploit, across 374 affected addresses. SecondFi separately secured 129 million ADA through emergency measures and is holding those funds in a third-party custodian for affected users pending verification.

Is Cardano or IOG responsible for the SecondFi exploit?

No. Cardano founder Charles Hoskinson confirmed that IOG has no ownership, control, or business relationship with SecondFi. The Cardano blockchain itself was not compromised. The vulnerability was in SecondFi’s own wallet generation software, which was built by Emurgo, the for-profit arm of the Cardano ecosystem.

What should SecondFi users do after the exploit?

SecondFi advised users not to restore their recovery phrases into new Cardano wallets, as that does not eliminate the risk from compromised addresses. Users should wait for SecondFi’s official post-mortem and follow only official platform guidance rather than informal community advice until a verified recovery process is published.

This article is for informational purposes only and does not constitute investment advice. Every investment and trading decision involves risk. Readers should conduct their own research before making any financial decisions.

Share With Your Network :

Facebook
X
LinkedIn
Pinterest
Reddit
Telegram
WhatsApp
Email
Threads

James Wright

James Wright is a Crypto News Reporter at TheCryptoWorld, covering breaking developments across exchanges, regulation, and institutional adoption. With a journalism background rooted in business reporting, James transitioned to full-time crypto coverage in 2020 after covering the rise of decentralized finance for an independent fintech publication. He focuses on delivering fast, accurate reporting on the stories that move markets — from SEC enforcement actions to major exchange listings and corporate treasury moves.
0 0 votes
Article Rating
Subscribe
Notify of
guest

4 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Kai Brennan
Kai Brennan
1 month ago

374 addresses hit but only 16M ADA drained averages out to small per-wallet balances, so this was probably a wallet-software user base not whales. address-level key gen flaw is the scary part though, was it deterministic derivation gone wrong or entropy collapse?

Priya Venkatesh
Priya Venkatesh
1 month ago

another self-custody wallet shipping prod code without a third party audit of the key derivation path. we keep learning the same lesson every cycle and pretending its new.

Mateo Rossi
Mateo Rossi
1 month ago

reminds me of the Profanity vanity address bug in 2022, same root cause class. predictable entropy in address generation has been a known footgun for years and teams still ship it.

Jay Tanaka
Jay Tanaka
1 month ago

how did SecondFi disclose this to affected users, on chain message or just a tweet?

Table of Contents

Check also

Specific Crypto details

Fear & greed index
49
▲ +4 from yesterday
Updated: April 11, 2026
▼ Fear
Recovering from extreme fear
0
Extreme fear
25
Fear
50
Neutral
75
Greed
100
Extreme greed
Yesterday
45
Fear
Last week
30
Fear
April 8
11
Extreme fear
0 0 votes
Article Rating
Subscribe
Notify of
guest

4 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Kai Brennan
Kai Brennan
1 month ago

374 addresses hit but only 16M ADA drained averages out to small per-wallet balances, so this was probably a wallet-software user base not whales. address-level key gen flaw is the scary part though, was it deterministic derivation gone wrong or entropy collapse?

Priya Venkatesh
Priya Venkatesh
1 month ago

another self-custody wallet shipping prod code without a third party audit of the key derivation path. we keep learning the same lesson every cycle and pretending its new.

Mateo Rossi
Mateo Rossi
1 month ago

reminds me of the Profanity vanity address bug in 2022, same root cause class. predictable entropy in address generation has been a known footgun for years and teams still ship it.

Jay Tanaka
Jay Tanaka
1 month ago

how did SecondFi disclose this to affected users, on chain message or just a tweet?

Binance Lists Microsoft Meta Tokenized Stocks Amid $347B RWA Token Surge

Exchanges

4 weeks ago

Binance Lists Microsoft Meta Tokenized Stocks Amid $347B RWA Token Surge

James Wright

Bitcoin ETF Outflows Hit $4.5B as BTC Falls Below $59K

Bitcoin

4 weeks ago

Bitcoin ETF Outflows Hit $4.5B as BTC Falls Below $59K

James Wright

Citi Bitcoin Price Target Cut to $82,000 as ETF Flows Dry

Bitcoin

4 weeks ago

Citi Bitcoin Price Target Cut to $82,000 as ETF Flows Dry

James Wright

Solana RWA Network Hits $3.4 Billion All-Time High

Altcoins

4 weeks ago

Solana RWA Network Hits $3.4 Billion All-Time High

James Wright

Market Analysis

The Future of Crypto, Covered Daily

Real-time news, expert analysis, and market insights  trusted by thousands of crypto investors worldwide.

You have been successfully Subscribed! Ops! Something went wrong, please try again.
4
0
Would love your thoughts, please comment.x
()
x