T
iTokenly

SecondFi (formerly Yoroi Wallet) hack — June 2026

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedJune 23, 2026
Target typeWallet software or provider
Loss$2,400,000Published estimates range $2,400,000 to $2,600,000Price at time of incident
MethodPrivate key compromiseSecondFi's wallet software generated per-transaction signatures using a nonce that was not sufficiently random. The company's own notice states that a value which should have been derived from secret information could, under certain conditions, be computed from public transaction data. Each signature therefore leaked information about the signing key, and an attacker with enough signatures from an address could reconstruct its private key and sign transactions itself. Because the exposure is at the key level, restoring the same seed phrase in a different wallet does not remove the risk.
ChainsCardano
OutcomeProject shut down

What happened

SecondFi is the rebranded Yoroi wallet, the Cardano light wallet built by EMURGO, one of the network's founding entities and the chain's largest wallet provider. Between roughly 21 and 23 June 2026 attackers drained about 16.1 million ADA, worth around $2.4 million at the time, from 374 addresses across several waves.

The cause lay in SecondFi's own key handling rather than in Cardano. The company's incident page describes a cryptographic flaw in per-transaction signing in which a value that should have been derived from secret information could, under certain conditions, be computed from public transaction data. SecondFi characterises this as a deterministic nonce derivation flaw that leaked enough information to mathematically reconstruct an address's private key from public blockchain data alone. EMURGO warned that affected wallets are compromised at the address and private-key level, and instructed users not to restore their recovery phrase into another Cardano wallet, because doing so does not mitigate the risk. Immunefi chief executive Mitchell Amador said the vulnerability lay in the code that generates the keys rather than in the blockchain, and noted that attackers have increasingly shifted toward the infrastructure that creates or stores crypto keys.

Roughly 129 million ADA held in wallets generated by the same software was moved into third-party custody before it could be taken. SlowMist founder Yu Xian, tracking the attackers on-chain, estimated that user losses could ultimately exceed $20 million, covering up to that 129 million ADA, because many wallets built with the flawed software remained exposed rather than already emptied. That figure describes funds at risk, not funds stolen. The confirmed theft remains about 16.1 million ADA, valued at approximately $2.4 million in most reporting and about $2.6 million in SecondFi's own notice.

EMURGO placed the wallets in a view-only quarantine mode, said SecondFi will not resume normal operations even after the audits are complete, and is winding down both SecondFi and Yoroi while running a recovery process for affected users, including a wallet-status checker, a secure export tool and an on-chain recovery system pending external audit. Charles Hoskinson said Input Output Global wrote none of the code and has no ownership, control or business relationship with the product.

Sources

  1. SecondFi / EMURGOPrimary · retrieved 2026-08-01
  2. CointelegraphSecondary · retrieved 2026-08-01
  3. The DefiantSecondary · retrieved 2026-08-01
  4. BanklessTimesSecondary · retrieved 2026-08-01

Official post-mortem: https://kb.secondfi.io/en/article/security-incident-update-dxv72a/

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "SecondFi (formerly Yoroi Wallet) hack — June 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/secondfi
https://itokenly.com/hacks/secondfi

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.