Cardano DeFi project warns of private-key generation vulnerability
SecondFi, the Cardano self-custody wallet formerly known as Yoroi, disclosed a flaw in its key-generation software. The defect exposed user private keys through predictable randomness, draining millions in ADA and leaving more at risk.
The vulnerability differs fundamentally from typical smart-contract exploits. Rather than affecting funds locked within a protocol, the flaw operates at the wallet infrastructure level, compromising private key generation itself. This root-level compromise leaves users exposed even if their assets have not yet moved on-chain.
Confirmed losses stand at roughly 16 million ADA, about $2.4 million, across approximately 178 wallets, according to SecondFi. Blockchain security firm SlowMist estimates total exposure could exceed $20 million, potentially involving up to 129 million ADA. The gap between confirmed and projected figures reflects that not all vulnerable wallets have been drained, keeping the risk window open after disclosure.
Emurgo, one of Cardano’s three founding entities, built Yoroi, which raises the reputational stakes, since the flaw sits in infrastructure tied to the ecosystem’s origins rather than an unaffiliated third party. Charles Hoskinson acknowledged the incident, noting the losses, though small relative to other exploits, offered no comfort to affected users.
SecondFi disclosed the incident on June 23, suspended services, entered maintenance mode, and took a snapshot of user balances. It has engaged a blockchain security firm for an independent review and is coordinating with Cardano ecosystem bodies including Input Output Global, the Cardano Foundation, and SundaeSwap.
The company warned that restoring a compromised seed phrase to another app does not remove the risk, since the flaw lies in key generation itself. Scammers impersonating SecondFi support have since targeted affected users with fake recovery tools.
What makes wallet-level compromises more dangerous
With a smart-contract exploit, users can identify the affected protocol and pull funds from it. A key-generation flaw offers no such signal. If the randomness was predictable, an attacker may already hold the keys to wallets that still appear untouched on-chain. The owner has no way to know until an unauthorized withdrawal occurs. Waiting to see whether funds move is therefore not a safe strategy.
Users with potentially affected wallets face a critical choice. The safest response is migration to newly generated wallets created with uncompromised software. That step closes the risk window even if an attacker already holds the leaked keys.