SecondFi is live. 🟦
If you’re a new user, download from https://t.co/IvQhMvzWk8.
If you’re coming from @YoroiWallet, your app auto-updates.
Reminder: SecondFi will never DM or ask for anything.
📖 | https://t.co/0Q36l9OKN6
Moved from @YoroiWallet?
A few things work better now. 🟦
Your funds are exactly where you left them.
One wallet at a time, with your balance up front.
More in the knowledge base: https://t.co/bKkr86P0yT
Self-custody puts you in control of your funds.
It also means the safety part is on you.
Worth running through the basics:
▪️ Your recovery phrase stays with you. Nobody needs it, including us. Anyone who asks for it is trying to drain you.
▪️ You approve every transaction yourself, so actually read it first. Wrong amount, or an address you don't recognize? Don't sign.
▪️ Onchain, there's no undo button. The few seconds you spend checking the address are the only protection you get.
Need help? One portal: https://t.co/C5s1yFPlq1. There is no support on X. Anyone in your replies or DMs offering to recover your funds is running a scam.
🚨 An Important Security Update from the SecondFi Team
We identified a security issue impacting a small number of Cardano wallets on our platform. We have contained the issue and paused the affected functions. Our engineering teams are actively working to restore full functionality to the platform.
To protect our users, SecondFi has been temporarily placed into maintenance mode. All front-end interactions are paused.
🚨 SECURITY UPDATE: Root Cause & Blast Radius Confirmed
We have isolated the root cause of the recent security incident. The issue was confined to our native Cardano web wallet generation software.
Our team has completed an onchain analysis to determine the scope of impact, and we are now finalizing an independent technical review with a leading blockchain security firm to validate our findings.
We're aware of the incident reported by @secondfiapp and @Ctrl_Wallet and are monitoring the situation closely.
First and foremost, our thoughts are with the affected users. Security incidents impact real people, and we appreciate the transparency shown by the teams as they investigate and work toward resolution.
The safety and security of our users is at the heart of everything we do. We remain vigilant in our approach to security and continue to monitor the broader ecosystem as more information becomes available.
We encourage everyone to stay cautious and follow updates from official project channels.
We'll continue to keep a close eye on developments and share updates if there's anything relevant for Lace users.
There has been conflicting advice from different community members in an attempt to be helpful.
⚠️ DO NOT RESTORE your recovery phrase into a new Cardano wallet.
As advised, do nothing until official steps come from SecondFi. The only thing you should do is submit a ticket at https://t.co/bKfl8SK9D2.
We will never DM you first or ask for your recovery phrase.
To provide more clarity, we have identified the nature of the incident, it is at the address level. The security risk affects wallet users when a transaction is signed.
Therefore recovery to another platform or wallet does not mitigate the risk.
🚨 DO NOT restore your recovery phrase into a new Cardano wallet.
We have isolated the affected wallets and will post mitigation steps shortly.
As per our previous post:
https://t.co/LGhovIoI3T
We have identified the root cause and have since rolled out a patch for all unaffected wallets. This will allow us to resume normal operations soon.
-----
Regarding affected wallets, 4 distinct draining events occurred. 3 were executed by external threat actors, resulting in a loss of ~16m ADA across 374 addresses.
To prevent total loss during the active exploit, emergency rescue measures were triggered to secure the available ~129m ADA and continues to be routed to an independent, qualified third-party custodian, where they are held securely for the benefit of the affected wallet addresses.
An external accounting firm has been engaged for a special audit to independently verify those holdings.
We are working to facilitate the verification process so users can claim back their assets safely. Affected users should submit their claim at https://t.co/bKfl8SK9D2
We take this incident seriously and are working to ensure all assets are returned to affected users as soon as possible.
As stated, we have identified the root cause, it is at the address level. Please DO NOT RESTORE your recovery phrase into another Cardano wallet, this does not mitigate the security risk. The security risk occurs when an affected user signs a transaction.
Further explanation to follow.
⚠️ As stated, we have identified the root cause, it is at the address level. Please DO NOT RESTORE your recovery phrase into another Cardano wallet, this does not mitigate the security risk. The security risk occurs when an affected user signs a transaction.
In addition, we are working to facilitate the verification process so users can claim back their assets safely so the above is very important, as it makes claims more difficult.
There has been conflicting advice from different community members in an attempt to be helpful. Do nothing until official steps come from SecondFi.
The only thing you should do is submit a ticket at https://t.co/bKfl8SK9D2.
We will never DM you first or ask for your recovery phrase.
Important Security Update.
As stated, we have identified the root cause of the incident. It is at the address level.
The affected software signer used a deterministic nonce derivation flaw. Every time an address signed a transaction, it leaked enough information to mathematically reconstruct that address's private key from public blockchain data alone.
If you were affected by the attack, your first/default address (index 0) is almost certainly exposed. It is the address that some wallets may be using by default or as the only address at all, and nearly always has transactions. That history is all an attacker needs.
Please DO NOT RESTORE your recovery phrase into another Cardano wallet. This does not mitigate the security risk.
Your keys are derived from your recovery phrase, not from the app. Restoring the same phrase into another wallet recreates identical addresses with identical exposure. The compromised thing is the key of the compromised address(es), not the interface you are using.
If you were affected by the attack, and use any of your compromised address(es) to deposit it could be drained again. This includes withdrawing staking rewards even using another wallet.
Reward withdrawal and delegation are signed with the stake credential. The withdrawn funds could be routed to your first/default address (as indicated above), which has a high chance of being compromised (wallets work differently managing it). Mempool-monitoring adversaries can front-run or sweep your assets on confirmation.
There has been conflicting advice from community members in an attempt to be helpful. Do nothing until official steps come from SecondFi.
We are working to facilitate the verification process so users can claim back their assets safely. Following the above is very important, if not it makes verified claims more difficult.
The only thing you should do right now is submit a ticket at https://t.co/bKfl8SK9D2
We will never DM you first or ask for your recovery phrase.
⚠️ Security Alert: Fake Support Emails and Websites
We are seeing fraudulent support emails and fake websites impersonating SecondFi to target affected users. Do not respond, do not click any links, and do not enter your details.
SecondFi does not provide support through Gmail or any personal email account, and our only official domain is https://t.co/C5s1yFPlq1. Always check the address carefully and do not trust links shared with you.
SecondFi will never email, DM, or message you first, and we will never ask for your private keys, recovery phrases, or wallet credentials.
Do not trust any checker, link, or account outside our official channels:
▪️ X accounts: @secondfiapp and @secondfi_jp
▪️ Support portal: https://t.co/bKfl8SK9D2
▪️ Asset recovery wallet checker: https://t.co/EGLOj6iKDl
SecondFi will not resume normal operations, even once the audits are complete.
Going forward, our involvement in @secondfiapp is limited to a dedicated asset recovery team, tasked solely with returning assets to affected users.
This is where our full focus and resources are directed.
Your Options for Securing Assets, and What’s Next
We recognize that some users may not have completed all steps in the Hardware Wallet Guidance posted in our knowledge base. If you are not technically proficient, we recommend waiting for the secure wallet export functionality, which is currently intended to launch next week.
Here is an update on upcoming options:
• This week: Quarantine mode
We will enable quarantine mode, which will let users check whether a wallet address appears in preliminary incident-related data and submit a support ticket with the relevant wallet address.
• Next week: Secure wallet export functionality
We intend to deploy secure wallet export as the next phase of quarantine mode. This is intended to provide a safer way for users of varying experience levels to move assets to a new wallet.
• On potential asset recovery
As stated previously, we intend to support a process relating to potential asset recovery for users whose wallets are confirmed through the applicable process. Any such process remains subject to further investigation, verification, eligibility criteria, applicable terms and conditions, and technical implementation.
It is currently expected to involve a recovery tool using zero-knowledge proofs, initiated by users through a portal, designed to help users remain in control of the process while protecting their information.
Again, if you are not technically proficient, we recommend waiting for these options to go live. For now, you may submit a ticket at https://t.co/bKfl8SK9D2.
We will continue sharing updates as progress is made.
Today, we formally notified the entities that we will be stepping down from our duties as a member of the Pentad. We want to thank the members for their shared commitment to Cardano throughout our time working alongside them.
Our immediate priority is the @secondfiapp recovery process, and we are concentrating our resources where they are needed most. We believe this is the right decision for our users and for the ecosystem, and it reflects the standard of accountability we hold ourselves to as a founding entity of Cardano.
As stated by SecondFi, quarantine mode is being enabled this week, letting users check if a wallet address appears in preliminary incident data and submit a support ticket. Our intention is that next week, the secure wallet export will be deployed to help affected users safely move assets to a new wallet. On asset recovery, we continue to make progress with the recovery tool, initiated through a portal, that keeps users in control while protecting their information
SecondFi / Yoroi Wallet Guidance Sessions in Tokyo and Osaka
We are hosting dedicated in-person guidance sessions during for SecondFi and Yoroi Wallet users affected by the security incident.
Each session will include:
- A SecondFi / Yoroi update from our CEO
- A live Q&A with our specialists
- Migration guidance slides
Our team will answer your questions and walk you through best practices for securing your wallet, or safely migrating it using the secure wallet export functionality, which will be released soon.
Please note the guidance slides are informative only. We will not conduct 1:1 or hands-on wallet troubleshooting.
EVENT DETAILS:
📍 Tokyo: Melody Line Hall, 1F, WebX Venue
(The Prince Park Tower Tokyo, Minato City)
📅 Tuesday, 14 July 2026, 12:00 to 18:45 JST
Register here: https://t.co/wUwmLIEZbi
📍 Osaka: TKP Garden City Umeda Osaka
📅 Saturday, 18 July 2026, 12:00 to 17:45 JST
Register here: https://t.co/tpTZ5ZuHHY
Sessions are held in English and Japanese. Registration via Luma is required for both, and support is first-come, first-served.