A security breach at SecondFi, the EMURGO-backed Cardano web wallet previously known as Yoroi Wallet, may be far larger than the company first reported. While SecondFi’s initial findings pointed to the theft of about 16 million ADA, outside analysis now suggests wallets linked to the attacker handled more than 129 million ADA and additional tokens.

Initial disclosure and revised estimates

SecondFi said earlier this week that attackers exploited a flaw in its proprietary wallet-generation software. In its preliminary account, that weakness allowed the theft of roughly 16 million ADA, which the report said was worth about $2.4 million at the time.

New scrutiny followed after Yu Xian, also known as Cosine, the founder of blockchain security firm SlowMist, reviewed transactions involving wallets believed to be connected to the exploit. Based on those fund movements, he said total user losses may have exceeded $20 million. He wrote that more than 129 million ADA, along with several other tokens, appeared to have passed through addresses associated with the attacker.

Community reaction inside Cardano

The incident has prompted criticism and concern across the Cardano community, not only over the security lapse itself but also over what it could mean for trust in related institutions.

Community member David said the breach was especially alarming because users lost funds without signing transactions. He also drew attention to SecondFi’s role in Cardano governance, saying the wallet provider controls one of the largest DRep delegations and that the episode raises broader questions about decentralization and trust.

Another community member, Dori, described the breach as one of the most serious incidents the ecosystem has faced. Dori argued that the fact a wallet tied to a Cardano founding organization was compromised makes the fallout particularly damaging for the network’s reputation.

Wallet flaw, not blockchain failure

As criticism spread, some participants in the ecosystem sought to separate the incident from Cardano’s underlying blockchain. Crypto analyst Dan Gambardello said claims that Cardano itself had been hacked were misplaced.

According to Gambardello, the vulnerability was in SecondFi’s key-generation process rather than in Cardano’s protocol, consensus design, or base infrastructure. That distinction has become a central part of the discussion as users and commentators try to determine whether the event reflects a wallet software failure or a deeper network problem.

Conflicting user guidance during investigation

In response to the breach, Cardano infrastructure provider Blink Labs warned anyone who created wallets through SecondFi to assume those wallets were compromised. The company said users should create a new wallet using trusted software from official sources, move their assets, and choose a new stake pool and DRep delegation.

SecondFi, however, told users not to restore their recovery phrases in other Cardano wallets while the investigation continues. Instead, it asked affected users to submit support tickets and wait for official instructions. The company said further guidance would come after an independent security review is completed and the exact nature of the vulnerability is fully understood.

The case remains under investigation, and the gap between SecondFi’s initial estimate and the larger figures cited by SlowMist highlights the uncertainty still surrounding the full scale of the breach. For now, the incident stands as a serious test for a wallet backed by one of Cardano’s founding organizations, while ecosystem participants continue to debate its implications for security, governance, and user confidence.

Source: thecryptobasic.com