Skip to main content
AVOID.NET
← SecondFi (Cardano Wallet)reviewed 2026-09-07 · 22 claims checked

Fact-check findings

What an automated fact-checker found when it re-read SecondFi (Cardano Wallet) against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

4 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #7[disputed][awaiting moderator]in section: Attack Scope and On-Chain Forensics
    “SecondFi's internal investigation identified two distinct threat actor groups that executed four separate automated wallet-draining campaigns.”
    reviewerSecondFi's investigation identified two threat actor groups that executed four separate automated wallet-draining campaigns.The page's own body text only describes three attacker-driven waves (Wave 1, Attacker A's second wave, and Attacker B's third wave). The 'four campaigns' figure appears to originate from SecondFi's own count of four total wallet-draining events, one of which was SecondFi's own defensive custodial transfer rather than an attacker campaign; attributing it to 'two threat actor groups' is not supported.
    Proposed correction (not yet applied)
    SecondFi's internal investigation identified two distinct threat actor groups that executed three separate automated wallet-draining campaigns.
  2. #8[disputed][awaiting moderator]in section: Attack Scope and On-Chain Forensics
    “drained approximately 12 million ADA from 198 wallets, liquidating stolen tokens through the Minswap decentralized exchange”
    reviewerWave 1 (Attacker A, June 21) drained approximately 12 million ADA from 198 wallets, liquidated through Minswap.The page appears to conflate two incompatible datasets: SecondFi's official 374-wallet count (Attacker A = 171 wallets across both waves, Attacker B = 203 wallets) and Bitquery's larger 3,072-wallet forensic count (its own 'wave 1'/'wave 2' split of 198/2,874). Presenting 198 as the wallet count for Attacker A's Wave 1 is mathematically inconsistent with the reported 171-wallet total for Attacker A across both of its waves.
    Proposed correction (not yet applied)
    drained approximately 12 million ADA from a portion of the 171 wallets Attacker A is reported to have compromised across both waves, liquidating stolen tokens through the Minswap decentralized exchange
  3. #9[disputed][awaiting moderator]in the timeline
    “draining approximately 12 million ADA from 198 wallets”
    reviewerTimeline: first wave (June 21, ~8:29 PM UTC) drained approximately 12 million ADA from 198 wallets.Same underlying dataset-conflation issue as the corresponding claim in the 'Attack Scope and On-Chain Forensics' section; the wave-1-specific 198 figure comes from Bitquery's separate, larger forensic dataset rather than SecondFi's official Attacker A count.
    Proposed correction (not yet applied)
    draining approximately 12 million ADA from a portion of the 171 wallets Attacker A is reported to have compromised across both waves
  4. #13[disputed][awaiting moderator]in the timeline
    “A second attacker's hub wallet sweeps approximately 135 million ADA from 2,874 wallets, transferring 129,430,001 ADA to a dormant vault in seven transactions.”
    reviewerTimeline (June 23): a second attacker's hub wallet swept approximately 135 million ADA from 2,874 wallets, transferring 129,430,001 ADA to a dormant vault in seven transactions.This timeline entry places SecondFi's official 203-wallet Attacker B figure in the same sentence sequence as Bitquery's much larger 2,874-wallet forensic figure without clarifying they come from different datasets covering different wallet populations, creating a misleading impression of a single reconciled figure.
    Proposed correction (not yet applied)
    Bitquery's forensic reconstruction separately found that, within its larger 3,072-wallet dataset, a hub wallet swept approximately 135 million ADA from 2,874 wallets, transferring 129,430,001 ADA to a dormant vault in seven transactions.

unverifiable

1 claim

No source the reviewer could reach confirms or contradicts the claim.

  1. #2[unverifiable][awaiting moderator]in section: Background and Ownership
    “which served over one million users and was one of the earliest and most widely adopted light wallets for Cardano”
    reviewerYoroi Wallet served over one million users prior to rebranding.Neither of the two cited official sources states a specific user count; the 'over one million users' figure could not be independently confirmed from a primary source, though it is a commonly repeated characterization in secondary coverage.

stale

3 claims

The claim was accurate when written but events since have overtaken it.

  1. #16[stale][awaiting moderator]in section: Company Response and Emergency Containment
    “EMURGO subsequently published a formal incident update confirming that wallet address mapping of all 374 affected addresses had been completed, and committed to full reimbursement through a dedicated independently secured restoration fund. As of the date of reporting, no specific compensation timeline, final audit results, or details of the restoration fund structure had been published.”
    reviewerEMURGO confirmed wallet address mapping of all 374 affected addresses was complete and committed to full reimbursement; as of the date of reporting, no compensation timeline, audit results, or fund structure had been published.The page's account of the disclosure was accurate at the time of the sources it cites (late June 2026), but is now superseded by EMURGO's July 22, 2026 announcement that the platform will not resume operations at all — a materially different outcome than the open-ended 'restoration fund, no timeline yet' framing the page presents. Notably, the page's own sources_used list includes archive timestamps from after July 22, 2026, yet the shutdown itself is not reflected anywhere on the page.
    Proposed correction (not yet applied)
    EMURGO subsequently published a formal incident update confirming that wallet address mapping of all 374 affected addresses had been completed, and committed to full reimbursement through a dedicated independently secured restoration fund. On July 22, 2026, EMURGO announced that SecondFi would not resume normal operations even after audits are complete, limiting its future role to asset recovery, and no final audit results or full compensation timeline had been published as of that announcement.
  2. #17[stale][awaiting moderator]in the summary
    “SecondFi is a Cardano self-custody wallet and neofinance platform operated by EMURGO, rebranded from Yoroi Wallet in April 2026.”
    reviewerSecondFi is a Cardano self-custody wallet and neofinance platform operated by EMURGO (present tense, summary).The summary describes SecondFi in the present tense as an operating platform, but as of July 22, 2026, EMURGO announced the platform would not resume normal operations and would be limited to asset recovery — a fact not reflected anywhere in the page.
    Proposed correction (not yet applied)
    SecondFi was a Cardano self-custody wallet and neofinance platform operated by EMURGO, rebranded from Yoroi Wallet in April 2026; EMURGO announced in July 2026 that SecondFi would not resume normal operations and would be limited to asset recovery.
  3. #18[stale][awaiting moderator]in section: Background and Ownership
    “SecondFi is a self-custody cryptocurrency wallet and financial platform developed by EMURGO, one of the three founding entities of the Cardano blockchain ecosystem alongside IOHK and the Cardano Foundation.”
    reviewerSecondFi is a self-custody cryptocurrency wallet and financial platform developed by EMURGO (present tense, Background section).Same underlying staleness issue as the summary: the opening sentence of the Background section describes SecondFi as a currently operating platform without acknowledging the July 2026 shutdown announcement.
    Proposed correction (not yet applied)
    SecondFi was a self-custody cryptocurrency wallet and financial platform developed by EMURGO, one of the three founding entities of the Cardano blockchain ecosystem alongside IOHK and the Cardano Foundation; EMURGO announced in July 2026 that SecondFi would not resume normal operations and would be limited to asset recovery.

partially supported

1 claim

The cited evidence supports part of the claim but not all of it.

  1. #12[partially supported][awaiting moderator]in section: Attack Scope and On-Chain Forensics
    “Bitquery's forensic reconstruction documented 3,072 victim wallets drained across both attacker campaigns, with 129.4 million ADA and 3,838 distinct token types moved in total.”
    reviewerBitquery's forensic reconstruction documented 3,072 victim wallets drained, with 129.4 million ADA and 3,838 distinct token types moved in total.The wallet count (3,072) and token-type count (3,838) are confirmed, but the '129.4 million ADA... moved in total' figure understates the report's own on-chain reconstruction total of roughly 141.9 million ADA; 129.4M appears to correspond specifically to the amount that ended up in the dormant vault (129,430,001 ADA) rather than the full amount moved across both waves.

confirmed

11 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in section: Background and Ownership
    “On April 22, 2026, at Money20/20 Bangkok, EMURGO formally introduced SecondFi as the successor product, describing it as a 'self-custody neofinance platform built for spending, trading, earning, and saving.'”
    reviewerYoroi Wallet rebranded to SecondFi at Money20/20 Bangkok on April 22, 2026, described as a self-custody neofinance platform.Rebrand date, venue and quoted description are corroborated by the official EMURGO press release and independent secondary coverage.
  2. #3[confirmed][no action needed]in section: Background and Ownership
    “The transition was handled automatically via app updates requiring no user action, and existing Yoroi wallet data, assets, staking positions, and governance delegations were preserved.”
    reviewerThe Yoroi-to-SecondFi transition was automatic via app update, requiring no user action, preserving assets and staking positions.Matches the source's own description of a seamless, automatic transition.
  3. #4[confirmed][no action needed]in the timeline
    “EMURGO announces Yoroi Wallet is rebranding to SecondFi at Money20/20 Bangkok, expanding into a self-custody neofinance platform with multichain support and global card payments.”
    reviewerTimeline entry: EMURGO announces the Yoroi-to-SecondFi rebrand on 2026-04-22.Consistent with official press release and secondary coverage.
  4. #5[confirmed][no action needed]in section: Exploit: Cryptographic Nonce-Derivation Flaw
    “Between June 21 and June 23, 2026, SecondFi's native Cardano web wallet generation software was exploited through a deterministic nonce-derivation flaw in its software signer.”
    reviewerBetween June 21-23, 2026, SecondFi's wallet software was exploited via a deterministic nonce-derivation flaw in its software signer.Dates and technical characterization are corroborated across multiple independent outlets and the Bitquery forensic report.
  5. #6[confirmed][no action needed]in section: Exploit: Cryptographic Nonce-Derivation Flaw
    “The Bitquery on-chain forensic report confirmed the weakness traced to 'weak randomness in SecondFi's key-generation code — not a flaw in Cardano itself.'”
    reviewerBitquery's report states the flaw was 'weak randomness in SecondFi's key-generation code — not a flaw in Cardano itself.'Near-verbatim match to the cited source's own language.
  6. #10[confirmed][no action needed]in section: Attack Scope and On-Chain Forensics
    “Attacker B independently conducted a third wave, compromising 203 additional wallets”
    reviewerAttacker B independently conducted a third wave, compromising 203 additional wallets.203 wallets for Attacker B is consistently corroborated and, combined with Attacker A's 171, correctly sums to the official 374-wallet total.
  7. #11[confirmed][no action needed]in section: Attack Scope and On-Chain Forensics
    “A single shared fee-funder address supplied approximately 7 ADA across 406 transactions during both waves, providing on-chain evidence that both attack groups shared common operator infrastructure.”
    reviewerA single shared fee-funder address supplied approximately 7 ADA across 406 transactions during both waves.Matches the Bitquery report's own figures closely.
  8. #14[confirmed][no action needed]in the timeline
    “SlowMist founder Yu Xian states total exposure including rescued funds may exceed $20 million”
    reviewerSlowMist founder Yu Xian stated total exposure including rescued funds may exceed $20 million.Attribution to Yu Xian/SlowMist and the $20 million figure are corroborated by multiple independent secondary sources.
  9. #15[confirmed][no action needed]in section: Company Response and Emergency Containment
    “SecondFi reported routing approximately 129 million ADA to an independent third-party custodian as a pre-emptive rescue measure, pending verification and return to affected users. An external accounting firm was engaged to verify custodied holdings.”
    reviewerSecondFi routed approximately 129 million ADA to an independent third-party custodian as a rescue measure, and engaged an external accounting firm.Corroborated by both contemporaneous and later reporting.
  10. #19[confirmed][no action needed]in section: User Risk: Seed Phrase Migration Warning
    “SecondFi explicitly warned that 'compromised keys remain exposed even if users import the same recovery phrase into another Cardano wallet,' and advised users to avoid independently transferring funds, withdrawing staking rewards, or attempting seed phrase migrations until official recovery instructions were issued”
    reviewerSecondFi warned that compromised keys remain exposed even if users import the same recovery phrase into another wallet, and advised against self-rescue via seed migration.The technical distinction the page draws — that reusing the same seed phrase does not create a new, safe key, whereas generating an entirely new wallet does — is consistent with independent reporting once the two pieces of advice are reconciled.
  11. #20[confirmed][no action needed]in section: Cardano Ecosystem Impact
    “At the time of the incident, ADA was trading at approximately $0.15, near its lowest level since 2020, which reduced the USD value of stolen funds relative to the ADA quantity involved.”
    reviewerAt the time of the incident, ADA was trading at approximately $0.15, near its lowest level since 2020.Price level and 'lowest since 2020' framing are corroborated by independent market coverage of the period.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.