On June 24, 2026, SecondFi, previously known as Yoroi and a native wallet of the Cardano ecosystem, suffered a security breach that resulted in the theft of approximately $20 million in ADA. The exploit came just days after the wallet completed its brand migration, raising serious concerns about infrastructure security at the core developer level.
Root Cause: Address-Level Vulnerability and Private Key Database Leak
Developed by Emurgo Labs, SecondFi served as a primary self-custody tool on the Cardano network. The transition from Yoroi to SecondFi was finalized on June 12. The exploit emerged shortly after. The SecondFi team confirmed that the vulnerability existed at the address level, triggered when a user signed a transaction. They stressed that simply transferring a seed phrase to another wallet would not mitigate the risk, urging users to move funds to a different type of wallet immediately.
Researchers warned that the vulnerability might not be limited to a small set of keys. All private keys generated through SecondFi could be compromised. The company traced the exploit back to its own wallet creation software.
Attack Method: Intercepting Recovery Transactions with Binance-Funded Wallet
On-chain data shows the attacker's address became active in the early hours of June 24. Although outflows have recently stopped, investigations found that stolen Cardano NFTs are held in a separate wallet. Blockchain analysts believe the attacker had prior access to a private key database. When a user initiated a recovery transaction, the attacker could identify the address and drain funds before the legitimate user completed the process. Some users only noticed the loss when attempting a transaction.
Additional research traced the attacker's initial funding to a Binance account, a detail that could aid in identifying the perpetrator.
User Response: Uninstall Wallet, Switch to Hardware Storage
SecondFi confirmed it has isolated compromised addresses but still advises users to uninstall both the wallet application and browser extensions and, where possible, transfer assets to a hardware wallet. So far, only the company's own interface has been suspended; the underlying smart contracts remain active.
ADA Price Pressure, Treasury Compensation Debate Unresolved
Following the breach, ADA's price dropped 2.9% in 24 hours to $0.15. Year-to-date, ADA has lost more than 54% of its value from $0.42 at the start of 2026 and has fallen out of the top 20 crypto assets by market capitalization.
The Cardano treasury still holds approximately 352.4 million ADA. A debate has emerged within the community over whether these reserves could be used to compensate affected wallet holders. No official decision has been made yet.

