
Cardano Ecosystem Pillar SecondFi to Terminate Services in Aftermath of $2.4 Million ADA Wallet Hack
Cardano-based 'Neo-finance' platform SecondFi has announced its permanent closure effective July 22, 2026, unable to overcome the aftermath of the 16 million ADA theft that occurred last June.
SecondFi, a Neo-finance platform that operated by integrating Yoroi, a major wallet service in the Cardano ecosystem, announced that it will permanently cease all services as of July 22, 2026. This decision follows a massive security breach in late June, which resulted in the theft of approximately 16 million ADA and caused irreparable damage to the platform's credibility. In an official statement today, SecondFi declared that it would no longer resume normal operations and would focus all future efforts on asset protection and supporting recovery for affected users.
Following the recent security incident, SecondFi has decided not to resume normal operations. Our sole priority moving forward is to protect assets securely and support recovery efforts for affected users.
The security incident that directly caused this shutdown was first reported on June 24, 2026. At that time, three consecutive attacks resulted in the theft of assets worth approximately $2.4 million to $2.6 million from 374 wallets. Immediately after the incident, SecondFi switched to maintenance mode to identify the vulnerability, but over 16 million ADA had already been transferred to the attacker's address. Just over a month after the incident, the platform ultimately made the extreme decision to terminate its services.
Technical Flaws and the Defense of 129 Million ADA
Investigations revealed that the hack originated from a cryptographic flaw within SecondFi's proprietary transaction signing software. Attackers exploited a vulnerability that allowed them to derive users' private keys from transaction data on the blockchain, thereby seizing control of self-custody wallets. Although the SecondFi team patched the vulnerability and prevented further leaks immediately after the incident, the exposure of fundamental security flaws in the software design phase drew fierce criticism from users.
- Total stolen assets: Approximately 16 million ADA (value at the time: approximately $2.4 million)
- Number of affected wallets: 374 in total
- Assets protected by white-hat intervention: 129 million ADA
- Balance of flagged addresses under tracking: Over 4 million ADA
Fortunately, the worst-case scenario of losing all assets was avoided. Thanks to the swift response from the Ccfi team and white-hat hackers, approximately 129 million ADA (worth about $18.5 million) was secured before it could fall into the attacker's hands. However, despite these defensive efforts, the $2.4 million loss already incurred and the damage to the brand's image proved to be too significant an obstacle for the platform to continue its operations.
Conflicts within the Cardano ecosystem also surfaced through this incident. On June 23, IOG's Charles Hoskinson clarified via his social media that Ccfi is not an IOG product and that IOG holds no equity or management control over it. He compared the situation to 'asking Apple about a problem with a Microsoft product,' drawing a clear line regarding the security failure of Ccfi, which is linked to EMURGO.
Victim Relief and Future Plans
As of July 22, 2026, a concrete compensation plan for the 374 affected users has not yet been finalized. EMURGO stated that it is currently preparing an official recovery plan and that the incident has been reported to law enforcement and relevant authorities, with investigations underway. Users are advised to check the status of their wallets and prepare supporting documentation in accordance with the recovery procedures to be announced in the future.
This incident has served as a wake-up call regarding wallet security within the Cardano ecosystem. The large-scale security breach, which occurred amidst a market situation where the price of ADA is trading near multi-year lows, has also negatively impacted investor sentiment. Experts warn that even for self-custody platforms, the existence of centralized vulnerabilities in signing software can lead to fatal consequences.
The exit of Ccfi and the Yoroi wallet marks a bitter end for a service that once served as a gateway to Cardano. The platform intends to focus on supporting users in withdrawing and transferring their assets during the remaining period and plans to release a detailed post-mortem report once further security reviews are completed.


This content is for information and commentary only and is not investment advice.
Join the reader conversation
Read reactions to this article and leave your own note.