The SecondFi team has announced the closure of its wallet on the Cardano blockchain following an attack that resulted in the theft of 16.1 million ADA.
An update regarding the recent security incident involving SecondFi
What happened to SecondFi
— SecondFi (@secondfiapp) July 22, 2026
Between June 21st and 23rd, SecondFi experienced a security incident that resulted in approximately 16.1 million ADA (~$2.6 million) being stolen from 374 wallets. We want to provide…
“The issue has been resolved, and it is known that this problem does not affect new wallets […]. However, given the seriousness of this event and as previously announced, we have made the difficult decision to cease operations of SecondFi and the Yoroi wallet,” the message stated.
The attack occurred from June 21 to 23. SecondFi estimated the value of the stolen assets at approximately $2.6 million. The Cardano blockchain itself was not compromised, and users of hardware wallets were unaffected by the incident.
The SecondFi wallet (formerly Yoroi until April) had long been a key player in the Cardano ecosystem. The application is backed by EMURGO, one of the three founding organizations of the network.
More on the Issue
According to SecondFi, the vulnerability was in the digital signature creation mechanism for transactions. A value that should have been calculated using secret information could, under certain conditions, be derived from publicly available blockchain data.
This allowed an attacker to reconstruct the private key data and sign transactions on behalf of the wallet owner. The flaw was in SecondFi's software, not in the Cardano protocol.
Beosin specialists linked the incident to an improper implementation of the Ed25519 digital signature algorithm.
When creating a signature, a nonce—a one-time value that should depend on secret data—is used. Beosin estimates that SecondFi's software generated it based on the public hash of the transaction without the necessary secret component. As a result, a single published signature could be sufficient to recover the private key.
SecondFi also discovered a copy of the vulnerable code that had been placed in a public GitHub repository without permission. The team is continuing to investigate the circumstances and is cooperating with law enforcement. However, the service does not claim that the attackers discovered the flaw through this repository.
Investigation Identifies Two Attackers
EMURGO has engaged the blockchain analytics firm Groom Lake for the investigation. Their specialists examined the code, change history, and transactions on the Cardano network.
Preliminary assessments suggest that the main attack was carried out by a technically skilled and well-funded external entity. Some indicators are being checked for possible links to the North Korean Lazarus group.
Groom Lake also identified a second attacker. According to analysts, this individual acted separately and withdrew funds from a different group of wallets during the same period. No overlaps between the affected addresses have been found so far.
According to SecondFi, the two attackers conducted three automated waves of attacks. The first withdrew funds from 171 wallets, while the second took from 203. In total, 374 addresses were affected.
Service Will Not Resume Normal Operations
The vulnerability has been fixed, and new wallets created with the updated software are not considered affected. However, EMURGO has decided to completely shut down SecondFi and the Yoroi wallet—the team's operational activities are now limited to refunding users and safely transferring remaining client assets.
The application is currently operating in isolation: users can view balances and addresses but cannot send, exchange, or transfer assets.
A secure wallet export function is planned for release in early August. This feature should allow users to transfer assets to a new wallet without reusing compromised data. A separate recovery portal based on zero-knowledge proofs is being developed for affected users.
As a reminder, at the end of June, EMURGO's head, Phillip Phan, indicated an estimated two-week timeline for initiating refunds.