Technical Mechanism and Vulnerability
Published 6/25/2026, 6:40:18 AM
On June 21, 2026, SecondFi (formerly Yoroi Wallet) suffered a critical security exploit resulting in a confirmed external loss of approximately 16 million ADA (~$2.4 million). The breach was caused by a flaw in the wallet's proprietary key-generation software, which used weak entropy to create predictable private keys rather than cryptographically secure ones.
Technical Mechanism and Vulnerability
The exploit did not target the Cardano blockchain itself but rather the client-side software used by SecondFi to generate user wallets.
- Weak Entropy: The core vulnerability was a lack of sufficient randomness during the key generation process. This allowed attackers to mathematically derive the private keys for addresses created using the flawed software.
- Address-Level Risk: Because the flaw is inherent to the specific private keys generated, importing a compromised seed phrase into a different wallet provider (such as Lace or Eternl) does not resolve the security risk. The keys remain predictable, and funds become vulnerable the moment a user signs a transaction.
- Attack Vector: The attacker utilized a single funding wallet to distribute gas (approximately 7 ADA per transaction) to multiple collector addresses, which then systematically drained the compromised wallets.
Timeline and Scope of the Incident
The exploit occurred in two primary waves, with SecondFi taking emergency measures to secure the majority of at-risk assets.
| Date | Event |
|---|---|
| June 21 (20:29 UTC) | First wave of draining begins; three collector addresses launched. [Note: Specific timing and address count not independently confirmed] |
| June 21–22 | Attackers liquidate Wave 1 funds (approx. 12.3M ADA) via the Minswap DEX. |
| June 23 | SecondFi publicly discloses the exploit, enters maintenance mode, and freezes balances. |
| June 24 | Official update confirms the root cause and outlines the claims process. |
While the immediate external theft was $2.4 million, the total scale of the incident was much larger. On-chain analysis suggests the total value of drained assets reached approximately 141.9M ADA (~$20 million) [Source: https://www.warpcast.com/velvet-unicorn/0x2eb3419e]. However, SecondFi successfully intercepted a significant portion of these funds.
Impact and Recovery
The exploit affected thousands of individual wallets across two distinct phases:
- Wave 1: Targeted 198 high-value wallets. [Note: Specific wallet count not independently confirmed]
- Wave 2: A broader sweep of 2,874 wallets. [Note: Specific wallet count not independently confirmed]
Current Status of Funds: SecondFi managed to secure 129.4 million ADA through emergency rescue measures. These funds have been moved to a secure, dormant vault managed by an independent third-party custodian. Affected users are advised to submit claims through the official support portal and avoid moving funds manually to prevent further exposure of predictable keys.
In summary, the SecondFi exploit was a client-side cryptographic failure that exposed $20 million in assets, though quick intervention limited the permanent loss to roughly $2.4 million. The incident remains a significant example of the risks associated with proprietary wallet-generation entropy.