SecondFi (formerly Yoroi), a major Cardano wallet built by EMURGO, exploited for 16M ADA due to a flaw in its private key generation software; 178 wallets drained with some users potentially uncompensated.
Security & Exploits ·
SecondFi, the Cardano wallet formerly known as Yoroi and built by EMURGO, suffered an exploit affecting 178 wallets due to a flaw in its private key generation software. Approximately 16 million ADA were drained across 374 addresses in three separate incidents executed by external threat actors, according to the wallet service's account. SecondFi stated that "some users may not be made whole," signaling potential uncompensated losses for affected holders.
The vulnerability resided at the address level, meaning users cannot mitigate the risk by restoring their recovery phrase to another wallet. During the active exploit, SecondFi triggered emergency measures to secure approximately 129 million ADA from affected wallets, which are now held by an independent third-party custodian. The team has patched the flaw and deployed fixes to unaffected wallets, enabling normal operations to resume.
SecondFi engaged an external accounting firm to audit the custodian's holdings and is directing affected users to submit claims at a support portal. The timeline for asset recovery and the full scope of uncompensated losses remain unclear, as does the precise mechanics of how the key generation flaw was exploited.