SecondFi has confirmed a security breach tied to its Cardano web wallet generation software, putting a core part of its wallet infrastructure under scrutiny. The company’s first estimate placed losses at about 16 million ADA. Independent analysis pointed to a much bigger number. SlowMist founder Yu Xian, known as Cos, said wallet activity and on-chain fund flows suggest total losses could theoretically exceed $20 million, involving more than 129 million ADA and other tokens.
Web wallet generation system identified as the source
According to SecondFi, the issue came from its native Cardano-based web wallet generation system, the component used to create new wallets and handle private keys. A flaw in that process allowed attackers to generate or access private keys linked to certain wallets. Users who created or used wallets through the web interface were the main group affected. Hardware wallets, along with older seed phrases that were not tied to the compromised generation flow, remained in a safer position.
User reports said drains continued for some time even after the team first detected the problem. That detail added pressure fast. SecondFi has since moved the platform into secure maintenance mode and taken a full balance snapshot to support compensation work for impacted users.
Yoroi legacy puts EMURGO under sharper pressure
The breach has drawn a stronger reaction because SecondFi was previously known as Yoroi, a wallet built by EMURGO, one of Cardano’s three founding entities. For many users, Yoroi was treated as a trusted ecosystem tool rather than an unproven wallet product. That history changed the tone of the response. Community members openly questioned why the official 16 million ADA estimate looked much lower than outside assessments and called for accountability from EMURGO beyond a simple apology.
Some users compared the incident to a bank being hacked during an upgrade that had not been fully tested. The comparison came from the community, but it showed how sharply trust had been hit.
Snapshot taken as review and compensation work continue
SecondFi said the full balance snapshot will serve as a basis for compensation tied to the attack. The team is working with IOG, the Cardano Foundation, IntersectMBO, and SundaeSwap in a coordinated response aimed at containing wider ecosystem damage. At the same time, an independent technical review is being finalized with a blockchain security firm to confirm the scale of the breach.
No stolen funds have been recovered so far, which is common in cases of this kind. Affected users have been asked to submit wallet addresses and transaction hashes through support channels, while the complete compensation framework is still being worked out.
Users urged to move funds from recently used web wallets
Security specialists are treating the incident as a broad warning for Cardano wallet users. Anyone who recently used a SecondFi or Yoroi web wallet has been advised to move remaining assets to a new, unrelated wallet address. A small test transfer first can reduce the chance of new mistakes during migration.
The source material highlighted several immediate precautions: move large holdings into hardware wallets such as Ledger or Trezor, avoid storing seed phrases digitally in photos or notes apps, and verify both the wallet URL and transaction details before signing. The technical review is still underway, and both the final damage scope and compensation details remain pending.

