GlenPost
Crypto

SecondFi Hack Puts Up to 129M Cardano (ADA) at Risk

A critical flaw in SecondFi's wallet generation software may have exposed more than 129 million ADA to theft.

Cardano's ADA token is under fresh pressure after a critical security flaw emerged in SecondFi, the EMURGO-backed Cardano wallet platform. The breach exposed a vulnerability deep inside the software that generates wallets and derives private keys, raising hard questions about how much damage has actually been done and what it means for the ADA price going forward.

At a Glance

  • ADA/USD is trading at $0.1515, down 4.3% on the day
  • SecondFi disclosed a flaw in its native Cardano web wallet generation software on June 23, 2026
  • SecondFi's own on-chain analysis pegs losses at roughly 16 million ADA (about $2.4 million)
  • Blockchain security firm SlowMist estimates losses could exceed $20 million, involving more than 129 million ADA
  • Around 178 wallets have been flagged by on-chain trackers, with suspicious activity concentrated June 21 to 22
ADA/USD CRYPTO:ADAUSD
Price0.1515
Day change-0.0068 (-4.3%)
Volume144,937,993

What Went Wrong at SecondFi

Most crypto security incidents come down to a smart contract bug or a phishing page. The SecondFi breach is different. The vulnerability lived inside the platform's wallet generation software itself, the code responsible for creating wallets and producing the private keys that control user funds. Think of a locksmith whose key-cutting machine was secretly making duplicates of every key it produced. Every wallet created through that compromised flow is potentially unsafe, regardless of how carefully the owner handled their credentials.

SecondFi moved quickly once the issue surfaced. The team paused all front-end activity, entered maintenance mode, and brought in an independent blockchain security firm to review the code. In its public statement, the project said: "We have isolated the root cause of the recent security incident. The issue was confined to our native Cardano web wallet generation software." Blink Labs, a Cardano infrastructure company, went further, publicly advising anyone who generated a wallet through the affected flow to treat it as unsafe and migrate funds immediately.

Cardano blockchain security breach

How Big Is the Damage, and Who Is Counting

Here is where the numbers diverge sharply. SecondFi's own preliminary on-chain analysis puts the total affected at roughly 16 million ADA, which at current prices works out to about $2.4 million. Serious, but arguably manageable for a platform with EMURGO, the commercial arm of the Cardano ecosystem, behind it.

SlowMist sees a much larger picture. Yu Xian, publicly known as Cos and founder of SlowMist, tracked two Cardano addresses he identified as suspected attacker wallets. His conclusion: users of the wallet have "likely lost over $20M," with the possible loss involving more than 129 million ADA along with other tokens. On-chain patterns, he noted, suggested the attacker obtained a batch of mnemonic phrases or private keys and then methodically drained larger wallets first before working down to smaller ones over many hours.

On-chain community trackers have identified around 178 affected wallets, with the bulk of suspicious transactions falling in the June 21 to 22 window. No stolen funds have been recovered, and SecondFi has not yet released a final technical report or any compensation framework.

Why SecondFi's Reputation Matters for Cardano

SecondFi is not some fringe third-party wallet. It is the direct successor to Yoroi, the self-custody Cardano wallet EMURGO originally launched as the ecosystem's primary retail entry point. When EMURGO rebranded the product as SecondFi and expanded its scope to cover spending, trading, earning, and saving, it was listed in Cardano's official app catalog. That institutional stamp of approval is exactly what makes this incident sting beyond the dollar figures.

History on other chains shows that wallet-layer exploits tied to officially endorsed products tend to leave a longer reputational mark than attacks on fringe tools. The Bo Shen $42 million wallet hack, which SlowMist later linked to a compromised mnemonic seed phrase, illustrated how exposure at the key generation level creates problems that linger well past the initial event.

Where ADA Stands Right Now

ADA was already in difficult territory before this week. The token fell below $0.20 in June and the current $0.1515 price represents levels last seen during the 2023 bear market trough. The roughly 12% shed over the past seven days reflects both the broader crypto market softness and the specific pressure from the SecondFi news. Crypto is volatile by nature, and single-day swings of several percent in either direction are common even without a security incident driving the action.

The path from here depends heavily on how the independent audit resolves and whether SecondFi produces a credible compensation plan. On the protocol side, the Van Rossem hard fork mainnet decision signals that Cardano's core development is continuing independently of the wallet-layer crisis, which at least separates the network's long-term roadmap from the reputational hit at the application layer.

Frequently Asked Questions

What exactly was the SecondFi security flaw?

The vulnerability was inside SecondFi's native Cardano web wallet generation software, the system that creates wallets and derives the private keys controlling funds. Any wallet created through that process may be compromised, even if the user handled their credentials carefully.

How much ADA was lost in the SecondFi hack?

SecondFi's own analysis puts the figure at approximately 16 million ADA, around $2.4 million at current prices. SlowMist founder Yu Xian estimates the real total could exceed $20 million, involving more than 129 million ADA and other tokens.

Is the Cardano network itself compromised?

No. The flaw was at the wallet application layer, not the Cardano blockchain protocol. The network itself continues to operate normally, and protocol development is ongoing.

What should SecondFi users do now?

Blink Labs publicly advised that any wallet generated through the affected software flow should be treated as unsafe. Users should consider migrating funds to a different Cardano wallet and monitor SecondFi's official communications for further guidance.

What to Watch Next

The gap between SecondFi's $2.4 million estimate and SlowMist's $20 million-plus figure is the most important number to watch. A final technical report and any compensation announcement will likely set the tone for ADA in the near term. Crypto carries significant volatility risk at the best of times, and an unresolved security incident at a flagship wallet compounds that uncertainty considerably.