SecondFi Exploit Drains $2.4M in ADA, Total Loss May Exceed $20M
SecondFi (formerly Yoroi) confirmed three external attacks exploiting a flaw in its proprietary wallet generation software, draining approximately 16 million ADA ($2.4 million) from 374 wallets. The vulnerability operates at the address level when a transaction is signed, so migrating seed phrases offers no protection. SecondFi rescued 129 million ADA before attackers could access it, routing funds to a third-party custodian and engaging an external accounting firm. Affected users must submit claims directly to SecondFi. Blockchain security firm SlowMist estimates total losses could exceed $20 million pending an independent audit, considering the full range of compromised wallets and tokens. Cardano founder Charles Hoskinson acknowledged the incident, noting the sum is modest compared to other crypto hacks but significant for victims. ADA trades near $0.15, its lowest since 2020.
Key facts
- Three attacks exploited flaw in SecondFi's wallet generation software.
- 16 million ADA ($2.4M) drained from 374 wallets; 129M ADA rescued.
- Vulnerability at address level; moving seed phrase ineffective.
- SlowMist estimates total losses could exceed $20 million.
- Affected users must submit claims directly to SecondFi.
KeyAudit data perspective
🔧 Check your seed against KeyAudit leak DB