SecondFi pins Cardano wallet hack on address-level bug
SecondFi traced a Cardano web wallet exploit to an address-level bug that exposed private keys, impacting about 16 million ADA while 129 million ADA was moved to a custodian.
SecondFi traced a security breach in its Cardano web wallet generation software to an address-level vulnerability that exposed private keys and allowed attackers to drain funds. The platform estimated roughly 16 million ADA, about $2.4 million, was affected across 374 addresses and said it secured about 129 million ADA by transferring those funds to an independent third-party custodian.
The company estimated the initial impact on Tuesday and reported it had identified the root cause and activated emergency measures by Wednesday. SecondFi has not published a full technical post-mortem and has focused public statements on containment, cooperation with investigators and holding secured funds for affected users while verification proceeds.
SecondFi described the flaw as occurring in the wallet software at the address level, affecting users when they sign transactions and leading to the exposure of private keys generated by the wallet. The platform advised users not to restore their recovery phrases into new Cardano wallets, saying restoration to another wallet does not mitigate the risk. Some members of the Cardano community urged affected users to migrate funds to newly created addresses; SecondFi has not adopted that guidance and continues to hold the secured ADA under custodial control pending claims verification.
Mitchell Amador, chief executive of security firm Immunefi, warned that the incident reflects attackers focusing on software that creates and stores cryptographic keys rather than the blockchain itself. He noted key-generation and address-derivation code often receives less audit scrutiny than smart contracts, which can leave wallet infrastructure vulnerable.
SecondFi rebranded from the Yoroi wallet in April 2026. Yoroi was developed by Emurgo, which identifies itself as a for-profit arm of the Cardano project. Charles Hoskinson, founder of Cardano, clarified that Input Output Global is separate from Emurgo and from SecondFi’s codebase, and he noted IOG’s incident response team has been in contact with the wallet and that SecondFi requested an independent security audit.
Background: Self-custodial wallets create and store private keys locally on users’ devices. When key-generation or address-derivation code contains a bug, the resulting private keys can be exposed and allow direct access to on-chain funds even if the underlying blockchain is secure. Security firms say vulnerabilities in wallet infrastructure can produce large losses because compromised private keys grant control of assets on the blockchain.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








