SecondFi, the Cardano wallet formerly known as Yoroi, confirmed losses of 16 million ADA worth about 2.4 million dollars from 374 user wallets in three attacks. The firm secured an additional 129 million ADA before further drains occurred. A flaw in its proprietary wallet generation software caused the breach.
The vulnerability operated at the address level, activating when an affected user signed a transaction. Moving a seed phrase to another wallet provided no protection. SecondFi rolled out a patch for unaffected users and advised affected customers to submit claims directly.
Blockchain security firm SlowMist estimated that total losses could exceed 20 million dollars across compromised wallets and tokens, pending an independent audit. SecondFi engaged an external accounting firm to verify recovered holdings and route them to a third-party custodian.
Cardano founder Charles Hoskinson acknowledged the incident, noting that the dollar amount was modest compared with other crypto hacks but offered little consolation to those affected. ADA traded near 0.15 dollars at the time, its lowest level since 2020.