Cardano wallet platform SecondFi has announced that it will wind down operations after a security breach led to the theft of approximately 16.1 million ADA, worth around $2.6 million. The decision comes weeks after the incident, with the company shifting its full attention to helping affected users recover their assets instead of continuing wallet development.
SecondFi said it will discontinue both the SecondFi and Yoroi Wallet platforms. While the vulnerability has been patched, the company stated that the seriousness of the incident left it with no choice but to cease operations and prioritize recovery efforts.
Investigation Points to Sophisticated External Attack
An independent forensic investigation by blockchain intelligence firm Groom Lake, commissioned by EMURGO, concluded that the attack was carried out by a sophisticated and well-funded external threat actor. Investigators also identified a second, unrelated attacker that targeted a different group of wallets during the same time period.
The investigation found that the exploit originated from a subtle cryptographic flaw in SecondFi’s transaction signature generation. Under certain conditions, the flaw could allow attackers to derive private key material using publicly available blockchain data. The company emphasized that the vulnerability affected the wallet software and not the Cardano blockchain itself.
- Approximately 16.1 million ADA stolen.
- 374 wallets were affected during the attack.
- The exploit occurred between June 21 and June 23.
- The vulnerability has since been patched for newly created wallets.
SecondFi Ends Operations
An update regarding the recent security incident involving SecondFi
What happened to SecondFi
Between June 21st and 23rd, SecondFi experienced a security incident that resulted in approximately 16.1 million ADA (~$2.6 million) being stolen from 374 wallets. We want to provide…— SecondFi (@secondfiapp) July 22, 2026
Despite fixing the vulnerability, SecondFi said rebuilding user confidence after such a significant security incident would be difficult. As a result, it has decided to permanently wind down the platform and redirect its remaining resources toward assisting affected users.
The company has also warned users to remain cautious of phishing attempts and fake support accounts while the recovery process is underway.
Recovery and Asset Migration Plans
SecondFi said its immediate focus is helping users recover and safely migrate their assets. Two key initiatives are currently in development:
- Zero-Knowledge Recovery Tool: A ZK-proof-based recovery portal is undergoing testing and will be independently audited before its planned release in August 2026.
- Wallet Export Feature: Users will be able to securely export their wallets and migrate assets to another Cardano-compatible wallet, with availability expected in early August.
The company has not announced a reimbursement program for affected users, instead focusing on technical recovery solutions and migration tools.
Crypto Platform Shutdowns Continue in 2026
SecondFi’s closure adds to a growing list of crypto platforms that have shut down following major security incidents in 2026. In March, Balancer Labs announced a lean restructuring after a $128 million exploit, while Summer.fi confirmed it would wind down operations in July following a $6.04 million vault exploit. Ctrl Wallet has also announced it will permanently shut down on August 3 after the Cardano security exploit, underscoring how increasingly sophisticated cyberattacks continue to force crypto projects to restructure or cease operations.
Impact on the Cardano Ecosystem
The shutdown marks one of the most significant wallet-related security incidents in the Cardano ecosystem. While Cardano’s blockchain infrastructure remained uncompromised, the breach highlights how vulnerabilities in wallet software can expose users to substantial losses.
The incident is expected to increase scrutiny of wallet security, cryptographic implementations, and third-party code audits across the crypto industry. For SecondFi, the coming months will be defined by the effectiveness of its recovery tools as it prepares to exit the market while assisting users affected by the exploit.

















