SecondFi Shuts Down after a wallet exploit Cardano wallet hack exposed a critical vulnerability in its transaction-signing system. EMURGO confirmed the platform won't return to normal operations after attackers drained 16.1 million ADA, worth about $2.4 million, from 374 wallets between June 21 and June 23, 2026.

Source : X Post
So how did the SecondFi hack actually happen? The flaw wasn't in Cardano itself. It was buried inside SecondFi's own signing code.
The wallet, which had replaced EMURGO's long-running Yoroi app, traced the root cause to a deterministic nonce error in its transaction-signing process.
A previous SecondFi Cardano wallet hack update and recovery investigation
No breach of the app required. No hack of the underlying network either. EMURGO was clear on that point, and hardware wallet users came through completely unaffected.
Quick facts:
Detail | Figure |
ADA stolen | 16.1 million (~$2.4M) |
Wallets affected | 374 |
Incident window | June 21–23, 2026 |
Emergency funds secured | 129 million ADA |
Estimated total exposure (SlowMist) | $20M+ |
There were four separate events during the attack window:
Three were external attacks, carried out by outside actors exploiting the same signing flaw
One was SecondFi's own emergency response, moving 129 million ADA into a third-party custodian before anyone else could touch it
That last move is worth pausing on. It's not every day a team manages to outrun its own vulnerability mid-attack, even if it couldn't save everything.
SecondFi Shuts Down permanently despite the availability of a patch. EMURGO SecondFi said the decision is final, with the company now focusing on user recovery, migration, and independent security audits.
A export tool is expected in August, alongside a dedicated recovery fund and outside audits. SlowMist, the security firm brought in to dig through the damage, thinks the real number could top $20 million once NFTs and other tokens are added to the tally.
The ADA exploit Value looks small next to Cardano's overall numbers, and that's worth putting in perspective. ADA currently trades around $0.173, per CoinMarketCap, giving it a market cap of roughly $6.31 billion and a rank of #15 among all cryptocurrencies. Out of a circulating supply of about 36.48 billion ADA, the 16.1 million stolen represents a tiny slice, well under 0.05% of everything in circulation.
While SecondFi Shuts Down marks the end of the wallet, the incident has not affected Cardano's tokenomics or the blockchain's core operations.
Metric | Value |
ADA current price | $0.1741 |
Market cap | $6.35B |
Circulating supply | 36.48B ADA |
24h trading volume | $276.89M |
ADA stolen as % of supply | ~0.044% |

Trading volume hasn't collapsed either, and 24-hour turnover remains active at over $280 million. That suggests the broader market hasn't treated this as an existential threat to Cardano itself, more as a wallet-layer problem contained to a single provider.
Still, incidents like this tend to weigh on sentiment even when the underlying chain is fine, and ADA's price has stayed well off its all-time highs through much of this stretch.
If there's one warning EMURGO wants to land, it's this: don't restore an old seed phrase into a new wallet. The problem lives at the address level, not the app level, so moving the same phrase somewhere else just drags the same exposure along with it.
Hardware wallets are the safer route forward, and they held up fine through the entire episode.
The 16.1 million figure is treated as confirmed for the moment, though it could shift once auditors finish tracing the fuller picture across NFTs and secondary tokens.
The whole thing has also stirred up a wider conversation about security across Cardano's ecosystem. One more thing worth flagging: EMURGO is warning users to stick to official channels only, since scammers are already impersonating the recovery process to hit victims a second time.
SecondFi Shuts Down following one of the most significant security incidents in Cardano Security recent history.
While the exploit exposed a flaw in SecondFi's transaction-signing implementation, EMURGO confirmed that the Cardano blockchain itself remained secure.
As recovery efforts continue, the incident serves as a reminder that security, regular software audits, and hardware wallets play a crucial role in protecting digital assets.
Disclaimer : This article is for educational and informational purposes only and should not be considered financial or investment advice. Always conduct your own research before making investment decisions.