Fresh stock news, updated daily
Crypto

SecondFi Hack Puts 129M ADA at Risk on Cardano

A flaw in SecondFi's Cardano wallet generation software exposed private keys across an estimated 178 wallets.

The SecondFi crypto hack, disclosed on June 23, 2026, exposed a flaw inside the platform's native Cardano web wallet generation software, the code responsible for creating wallets and deriving private keys. Damage estimates range from a conservative 16 million ADA to more than 129 million ADA, and no stolen funds have been recovered.

At a Glance

  • Vulnerability located in wallet generation software, not a smart contract bug or phishing attack
  • SecondFi's own on-chain analysis counts roughly 16 million ADA affected, worth about $2.4 million at current prices
  • SlowMist founder Yu Xian (Cos) estimates losses may exceed $20 million, involving more than 129 million ADA and other tokens
  • Approximately 178 wallets flagged by on-chain community trackers, with suspicious activity concentrated June 21 to 22
  • ADA was trading near $0.15 at disclosure, down roughly 12% over the prior seven days and close to 2023 bear market lows
Cardano blockchain security breach

What the Vulnerability Actually Was

Most wallet-layer exploits involve either a smart contract flaw or a front-end phishing site that tricks users into signing malicious transactions. The SecondFi breach fits neither category. The problem lived inside the wallet generation flow itself, the software that produces wallets and derives the private keys controlling user funds.

A useful analogy: imagine a locksmith whose key-cutting machine was quietly producing duplicate copies of every key it cut. Every customer who used that machine has a compromised lock, regardless of how carefully they stored their own key. That structural nature of the flaw is why Blink Labs, a Cardano infrastructure firm, publicly advised users to treat any wallet created through the affected system as unsafe and migrate immediately.

SecondFi says it has isolated the root cause. The team confirmed the issue was confined to the native Cardano web wallet generation software, paused all front-end activity, entered maintenance mode, and commissioned an independent technical review with a blockchain security firm. A final technical report and compensation framework have not yet been published.

The Gap Between SecondFi's Numbers and SlowMist's

The most consequential unresolved question right now is the actual scope of losses, and the two most credible data points are far apart.

SourceEstimated ADA AffectedUSD Value (at ~$0.15)
SecondFi preliminary on-chain analysis~16 million ADA~$2.4 million
SlowMist (Yu Xian / Cos)More than 129 million ADA plus other tokensMore than $20 million

Cos tracked two Cardano addresses he identified as suspected attacker wallets and characterized the picture as significantly larger than the platform's own estimate. His on-chain analysis suggested the attacker obtained a batch of mnemonic phrases or private keys and systematically drained accounts over many hours, targeting larger wallets first before moving to smaller ones. That pattern is consistent with an attacker who had bulk access to key material rather than opportunistic theft from individual users.

The divergence between $2.4 million and $20 million is not simply a rounding difference. It has direct implications for whether EMURGO, the commercial arm of the Cardano ecosystem and SecondFi's institutional backer, can absorb a compensation obligation or whether users face unrecovered losses.

Why SecondFi's Institutional Status Amplifies the Damage

SecondFi is the direct successor to Yoroi, the self-custody wallet EMURGO originally launched as the Cardano ecosystem's primary retail entry point. When EMURGO rebranded the product and expanded its mandate to cover spending, trading, earning, and saving, it retained placement in Cardano's official app catalog. This is not a peripheral third-party tool. It carries explicit institutional endorsement.

That provenance matters because historical data from wallet-layer exploits on other chains shows that reputational damage is more persistent when the compromised product has official backing. The Bo Shen $42 million wallet hack, which SlowMist later linked to a compromised mnemonic seed phrase, illustrated how seed phrase exposure creates recovery problems that outlast the initial incident by months. A flagship product with ecosystem endorsement failing at the key generation layer is a different category of event than an obscure third-party app being phished.

Ada price chart decline

ADA Price: Where It Stands and What Moves the Needle Next

ADA was trading near $0.15 at the time of disclosure, down about 3% in 24 hours and roughly 12% over the prior week. The token had already broken below $0.20 earlier in June, and $0.15 is territory last visited during the 2023 bear market trough. The SecondFi incident did not create ADA's weakness, but it compounds it at a technically fragile level.

The path forward for ADA price splits along two tracks depending on how the SecondFi audit resolves. If the independent review validates the lower $2.4 million figure, confirms the vulnerability is fully patched, and EMURGO announces a credible compensation plan, the incident is more likely to be priced in and fade. If the SlowMist estimate of more than $20 million holds, and no recovery or compensation materializes, the reputational overhang on the wallet layer could suppress retail confidence for a prolonged period. Protocol-level development, including the recent Van Rossem hard fork mainnet decision, continues independently of the wallet crisis, but protocol progress has historically struggled to offset wallet-layer trust deficits in the near term.

State-level threat actors add a further layer of risk. The North Korea-linked theft patterns documented at the G7 Evian summit showed how wallet-layer vulnerabilities across multiple chains can be exploited systematically, a dynamic that raises the stakes for any unpatched or incompletely disclosed key generation flaw.

Frequently Asked Questions

What exactly was hacked in the SecondFi breach?

The flaw was in SecondFi's native Cardano web wallet generation software, the code that creates wallets and derives private keys. Unlike a smart contract exploit or a phishing attack, this vulnerability may have exposed private key material for any wallet created through the affected system.

How many wallets and how much ADA were affected?

On-chain community trackers have identified around 178 affected wallets. SecondFi's own estimate puts losses at roughly 16 million ADA (about $2.4 million), while SlowMist's Cos estimated losses could exceed 129 million ADA and other tokens, worth more than $20 million.

Is the Cardano network itself compromised?

No. The vulnerability was at the application layer inside SecondFi's wallet software, not at the Cardano protocol level. The underlying blockchain continued operating normally, and protocol development such as the Van Rossem hard fork proceeded on its own schedule.

What should users who created wallets through SecondFi do?

Blink Labs and SecondFi both advised treating any wallet generated through the affected system as unsafe. Users should migrate funds to a wallet created through a different, unaffected platform as promptly as possible.

What to Watch as the Audit Progresses

Three data points will determine how this incident is ultimately categorized: the final loss figure from the independent technical review, whether EMURGO or SecondFi announces a compensation framework, and whether any of the stolen funds move through traceable on-chain paths. The gap between $2.4 million and $20 million is wide enough that the audit result alone could shift both the narrative and ADA's near-term price trajectory. Until that report is published, the 178 flagged wallets and the two suspected attacker addresses tracked by SlowMist represent the most concrete data available.