Cardano's ADA token is trading at $0.1515, down 4.3% on the day, after a security breach at SecondFi, the EMURGO-backed wallet platform that evolved from the original Yoroi wallet, exposed as many as 129 million ADA to theft and reignited questions about the chain's application-layer security posture.
At a Glance
- ADA/USD: $0.1515, down 4.3% on the day
- SecondFi disclosed a critical flaw in its native Cardano web wallet generation software on June 23, 2026
- SecondFi's own on-chain estimate: roughly 16 million ADA affected, approximately $2.4 million at current prices
- SlowMist founder Yu Xian (Cos) puts potential user losses above $20 million, involving more than 129 million ADA and other tokens
- Around 178 wallets flagged by on-chain trackers; no stolen funds recovered as of press time
| Price | 0.1515 |
|---|---|
| Day change | -0.0068 (-4.3%) |
| Volume | 144,937,993 |
What Happened at SecondFi
The vulnerability is not a smart contract bug or a phishing front end. It sits inside the wallet generation software itself, the code responsible for deriving the private keys that control user funds. Every wallet created through the compromised flow is potentially exposed, regardless of how carefully the user managed their own credentials afterward. Blink Labs, a Cardano infrastructure firm, publicly advised that any wallet generated through the affected system should be treated as unsafe and that users migrate to a new wallet immediately.
SecondFi confirmed it has isolated the root cause. In its security update the project stated: "The issue was confined to our native Cardano web wallet generation software." The platform suspended all front-end activity, entered maintenance mode, and engaged an independent blockchain security firm to conduct a technical review.

On-chain transaction patterns observed by SlowMist suggest the attacker obtained a batch of mnemonic phrases or private keys and drained wallets over many hours, targeting larger balances first before moving to smaller ones. Community trackers have concentrated suspicious activity in the June 21 to 22 window. No compensation framework has been announced, and no final technical report has been published.
The Gap Between Two Damage Estimates
The discrepancy between SecondFi's internal estimate and SlowMist's is substantial enough to matter for how the market prices the fallout. SecondFi's preliminary on-chain analysis puts affected funds at approximately 16 million ADA, roughly $2.4 million at current prices. EMURGO, the commercial arm of the Cardano ecosystem and SecondFi's institutional backer, has the resources to address a loss of that size.
SlowMist's Cos tracked two addresses he identified as suspected attacker wallets and arrived at a figure more than eight times larger. His assessment: users of the wallet have likely lost over $20 million, with exposure potentially exceeding 129 million ADA plus other tokens held in affected wallets. Until SecondFi publishes a verified on-chain accounting, the true scale remains unresolved, and the market is pricing for the wider scenario.
Why SecondFi's Institutional Pedigree Amplifies the Risk
SecondFi is the direct successor to Yoroi, the self-custody wallet EMURGO originally positioned as the Cardano ecosystem's primary retail entry point. When EMURGO relaunched the product under the SecondFi name with an expanded scope covering spending, trading, earning, and saving, it retained its listing in Cardano's official app catalog. This is not a peripheral third-party tool with a limited user base. It carries official ecosystem endorsement.
That distinction matters for the duration of the reputational damage. Wallet-layer exploits on other chains have historically caused more persistent price suppression when the compromised product had institutional backing, because the breach calls into question the security governance of the broader ecosystem, not just one team's code quality. The Bo Shen $42 million wallet hack, which SlowMist subsequently linked to a compromised mnemonic seed phrase, illustrated how seed phrase exposure creates problems that outlast the initial theft, complicating recovery efforts and sustaining uncertainty.
State-level threat actors have been documented exploiting wallet-layer vulnerabilities across multiple chains. The North Korea-linked theft pattern flagged at the G7 Evian summit is a reminder that a single ecosystem's wallet breach can attract attention well beyond that ecosystem's community.
ADA's Price Position and the Path Forward
ADA has shed roughly 12% over the past seven days. At $0.1515 the token is trading near territory last visited during the 2023 bear market trough, and the breach has arrived at a structurally weak moment. The token had already broken below $0.20 in June before the SecondFi disclosure, so the hack lands on a chart that offered little technical support to begin with.
The Van Rossem hard fork mainnet decision signals that protocol-level development is proceeding independently of the wallet-layer crisis, which provides some separation between network fundamentals and application security. But price recovery is likely conditional on two things: a credible, complete technical post-mortem from SecondFi that closes the question of scope, and a compensation framework that addresses affected users. Without both, the uncertainty premium stays embedded in the price.
Crypto markets are highly volatile, and ADA is among the more volatile major tokens. A resolution of the SecondFi audit that confirms the lower $2.4 million damage figure could reduce selling pressure quickly. Confirmation of the $20 million-plus figure would sustain it. The range between those two outcomes is wide, and that uncertainty is what the current price reflects.
Frequently Asked Questions
What exactly was the SecondFi vulnerability?
The flaw was in SecondFi's native Cardano web wallet generation software, the component that creates wallets and derives private keys. Any wallet generated through the affected system is potentially compromised, regardless of how the user stored their credentials.
How much ADA was stolen in the SecondFi hack?
SecondFi's own preliminary estimate is approximately 16 million ADA, around $2.4 million at current prices. SlowMist founder Yu Xian (Cos) put potential user losses above $20 million, involving more than 129 million ADA and other tokens. The final figure has not been confirmed.
Is the Cardano network itself compromised?
No. The vulnerability is at the application layer, inside SecondFi's wallet software, not in the Cardano protocol. The network continues to operate normally, as reflected by the Van Rossem hard fork proceeding on its planned course.
What should users who created wallets through SecondFi do?
Blink Labs advised that any wallet generated through the affected flow should be considered unsafe. Users are encouraged to migrate funds to a fresh wallet created through an unaffected platform. SecondFi has paused its front end while the security review is underway.
Where Things Stand
The SecondFi breach is a serious, unresolved incident affecting a flagship Cardano product at a moment when ADA was already trading near multi-year lows. Around 178 wallets have been flagged, the damage estimate spans a wide range, no funds have been recovered, and no compensation plan exists yet. The next concrete data points are SecondFi's independent security audit and any on-chain accounting that closes the gap between the platform's own figures and SlowMist's assessment. Until that clarity arrives, the price reflects the uncertainty.



