QooryBeta
Back to narratives
SecurityActive
Conversation intelligence

SecondFi (Yoroi) Security Incident: ~16M ADA Stolen

SecondFi, the Cardano wallet formerly known as Yoroi, suffered a security breach resulting in approximately 16 million ADA stolen due to a vulnerability in its native web wallet generation software. The Cardano blockchain itself was not compromised.

Heat
95
Confidence
95%
Evidence
8
Updated

Why It Happened

The root cause was in the wallet generation software that creates new wallets and recovery seed phrases, potentially exposing private keys from creation. The incident was isolated to the wallet software layer, not the Cardano chain.

Outcome So Far

SecondFi has isolated the root cause, put the wallet into maintenance mode, and is working to make affected users whole. Details on compensation and number of affected wallets are pending.

Actors

Timeline order

Post
Parent event 01

X conversation update

1 related posts from @CG_BRC20

Related posts@CG_BRC20
@CG_BRC20
Open on X9.7K views · 35 likes · 9 reposts

Post
Parent event 02

Initial reports of wallet draining

Users reported wallets being drained from Yoroi/SecondFi. The wallet was put into maintenance mode.

Related posts@Cardanians_io@Cardanians_io@jiaozibullish4 posts
@Cardanians_io
Open on X13.1K views · 248 likes · 24 reposts
@Cardanians_io
Open on X10.2K views · 69 likes · 16 reposts
@jiaozibullish
Open on X7.0K views · 60 likes · 3 reposts
@Cardanians_io
Open on X4.0K views · 32 likes · 4 reposts

Post
Parent event 03

X conversation update

3 related posts from @Cardanians_io, @yutazzz, @pawnie_

Related posts@Cardanians_io@yutazzz@pawnie_
@Cardanians_io
Open on X3.3K views · 150 likes · 23 reposts
@yutazzz
Open on X7.2K views · 52 likes · 11 reposts
@pawnie_
Open on X1.3K views · 37 likes · 1 reposts