SecondFi Is Shutting Down: Official EMURGO Recovery Update

Episode by Peter Bui on July 7th, 2026

EMURGO has published a new update on the SecondFi security incident, and the biggest takeaway is clear: SecondFi will not be returning to normal operations. The update focuses on asset safeguarding, recovery work, wallet status checks, and a safer migration path for users who may have been affected.

This matters because SecondFi was positioned as a successor to Yoroi, a wallet name many long-time Cardano users recognise. The incident has quickly become more than a single application issue. It is now a reminder that wallet security, recovery communication, and self-custody practices all matter when users are managing assets on-chain.

What EMURGO Has Confirmed

The episode walks through EMURGO’s public statement on the SecondFi incident. According to the official EMURGO update, multiple security firms have been engaged to review the issue, and the vulnerability identified so far has been patched.

EMURGO is not releasing every technical detail immediately. That is a sensible position while reviews continue and while malicious actors may still be looking for ways to exploit exposed information. In an active security situation, too much detail too early can create extra risk for users who have not yet moved or verified their funds.

The current focus is not marketing, product recovery, or relaunching the wallet. The focus is on asset safeguarding, fund recovery, and helping users understand whether their wallets were impacted.

SecondFi Is Ceasing Operations

The most important product update is that SecondFi will not resume normal operations. Peter frames this as the effective closure of SecondFi in its current form, which is significant given how recently the application launched.

There is also uncertainty around what this means for Yoroi in the long term. Yoroi has been part of the Cardano ecosystem for many years, and the codebase has open-source components, so it is possible that community members or other contributors could explore future paths. However, based on the current update, users should not assume SecondFi itself is coming back.

That makes the practical path more important than the brand story. Users need clear information, a trustworthy verification flow, and safe migration options. The next steps should be judged by how well they reduce risk for affected and unaffected users.

Wallet Status Checks And Recovery

EMURGO is working on a wallet status verification process. The goal is to let users determine whether their wallet was affected and what action they should take next. Peter notes that a previous tool was released, but the newer approach appears to be aimed at improving the user experience and making the checking process clearer.

A quarantine site is expected to help users verify wallet status and follow a migration pathway. This kind of flow is important because panic creates its own risks. Users dealing with a security incident are more likely to click fake links, follow unofficial advice, or rush into unsafe recovery steps. The safest approach is to use official channels, verify URLs carefully, and avoid signing anything that is not fully understood.

The episode also highlights that incident reports and code reviews are still being finalised. EMURGO has indicated that more detail will come later, once the process is complete and disclosure will not increase user risk.

Why Hardware Wallets Are Back In Focus

A major practical theme in the episode is hardware wallet migration. Peter explains that users who do not already use a hardware wallet should seriously consider one, especially when moving away from software wallets after a security event.

Hardware wallets can reduce exposure because signing happens on a separate device rather than directly inside a browser or hot wallet environment. Peter mentions Keystone and Ledger as examples that are widely used or supported in the Cardano ecosystem. The key point is not that one device is a perfect answer for everyone, but that self-custody requires layers of protection.

Users should buy hardware wallets through official channels, follow setup instructions carefully, and protect seed phrases offline. A hardware wallet does not remove every risk, but it can make common wallet compromise paths much harder.

What Users Should Do Next

The immediate advice is to stay cautious and wait for official recovery guidance. Users should monitor EMURGO and official SecondFi communication channels, check wallet status only through verified links, and be especially careful with direct messages, search results, and third-party recovery offers.

For unaffected users, the update suggests a migration pathway toward hardware wallets or alternative platforms. For affected users, the priority remains recovery and official instructions. In both cases, the bigger lesson is the same: wallet infrastructure is critical, and the Cardano ecosystem needs clear security standards, transparent incident handling, and strong user education.

This is a disappointing outcome for SecondFi, but the most important thing now is reducing user harm and getting reliable information into the hands of people who need to act.

Key Takeaways

  • EMURGO says the identified vulnerability has been patched, but further reviews are still underway.
  • SecondFi will not resume normal operations, making this effectively the end of the wallet in its current form.
  • The current priority is asset safeguarding, fund recovery, and wallet status verification for users.
  • A quarantine site is expected to help users check whether their wallets were impacted and follow safer migration steps.
  • Hardware wallet migration is now a practical focus for users who want stronger self-custody protections.
  • Users should rely only on official links and avoid rushed recovery actions or unsolicited help.

Disclaimer: This content is for educational and informational purposes only and is not financial, legal, or security advice. Always verify information through official sources and consult qualified professionals where needed.

Text Transcript

We have another major update from SecondFi around the hack and also the recovery of all the funds for users that have been affected. So let’s get right into this one here. This is the official statement from EMURGO at the moment around the SecondFi incident. Now, I’ll go through this summary really quickly for you guys to get to the point.

They’ve engaged multiple different security firms to conduct a review, and they have patched the current vulnerability that they have identified. And there may be more. So they’re not releasing all the details of it just as yet, because there may be more that I’ve found. And they do know that there are malicious actors at the moment trying to get more funds out of this particular exploit.

So please stay safe, guys. Now, at the moment, they are focusing on asset safeguarding and fund recovery. That is the main goal at the moment. And they’re working on a wallet status verification process and building that mechanism that allow users to determine whether their wallet was impacted.

So they did release one last week, but this is a slightly better one. I think a better user experience so that users can actually work out if their wallets have been compromised or not. Lastly is the migration pathway, a clear path, safe routes to migrate to hardware wallet solutions or alternative platforms using the quarantine methods. Now, this is also really important here.

They will be ceasing operations from now on. So although we believe unaffected users remain safe, SecondFi will not resume normal operations. This is essentially the closure of SecondFi. Literally one week into its release.

And it’s unfortunate now that the team will no longer be running the SecondFi project and continuing that particular wallet operation. This, I believe, also goes for Yoroi and its successor, SecondFi. So it’s really unfortunate because Yoroi has been around for a very long time. It’s not exactly clear if Yoroi will be restored or not, but it really doesn’t sound like it will be from the sounds of it.

But there may be a re-ignition of it by community members because the Yoroi wallet is open source. It does work very well for what it is, but it may need some upgrading to keep it up to date with the current evolution and growth of the Kedana ecosystem. But overall, this is a very sad news story from the SecondFi team to hear that the SecondFi app will be ceasing operations. It’s probably the best decision here.

And I think the main focus on on-chain recovery is the main thing for the team. So what comes next? This week, they will launch that quarantine site that makes it significantly easier for users to check the status of their wallet and take necessary actions to migrate. And it’s probably a really good time, guys, at the moment to look into hardware wallets.

If you don’t have a hardware wallet yet, I highly recommend the Keystone wallet. Brilliant hardware wallet. It’s air-gapped, uses QR codes to scan the information from your computer. It signs up on your wallet and then you use a QR code for your computer to read and then submit that transaction on-chain.

So it’s a brilliant hardware device, all open source and built very, very well. The other aspect, other wallet, I should say, is the Ledger. Ledger’s been around for a really long time, very well supported in the Kedana ecosystem. And it is quite an easy wallet to use, too.

There are some controversy around their recovery process and the embedded firmware that sends the seed phrases of where. But I think the simple model doesn’t have that built into it. So look at the simple one, it’s usually the cheapest as well. But I highly recommend if you don’t have a hardware wallet, look into getting one now, protect and secure your assets, take self-custody of them.

OK, links down below. I’ve got affiliate links to Keystone and the Ledger Nano as well. So if you’re interested in supporting the channel, you can buy through my affiliate links and you can buy it that way. I get a little bit of a cut of the commission and you get a brilliant hardware wallet.

But that’s OK. You can buy external. You don’t need to buy it, but make sure you don’t you don’t need to buy it through my affiliate links. But make sure you do buy it through the official channels itself.

OK, back to the story here. So they’ll be working through that recovery process and you’ll see everything come on chain hopefully later this week. Now, in terms of transparency here, we will publish on our we will publish on account of who and what and why once the incident reports and code reviews are finalised. It’s a complex situation.

The evidence suggests that a number of external threat actors may be involved. We understand the community is seeking answers and we share that urgency at this moment. However, our focus is where it must be. Safeguarding users, providing unaffected users a clear pathway to hardware wallets or alternative platforms and returning assets to those who were affected.

So there are two two main users that were affected by this entire process. The first one were the users that were hacked by the hacker themselves that found the exploit and managed to move, I think, was 16 million worth of ADA out of users’ wallets. And then also the White Hat hacker that moved 129 million worth of ADA and assets out of users’ wallets. So we’ll see the return of all of that in due course.

So the White Hat hacker is holding onto the assets. They’ll be returning that. But then also the extra funds that EMURGO themselves are forking out to return that first initial 16 million as well. What I would love to see and understand is where and what the hacker is doing with these funds.

We managed to trace it. We saw them convert a lot of the funds to USDCX. But what’s happening from there? I haven’t tracked and seen what else has happened there.

I would love to work out and find out who this person is or who they are and what is happening with the funds themselves. But very unfortunate to see SecondFi, Yoroi all come to this point. Now, what are people saying? A lot of spam emails going out at the moment.

If you received an email about SecondFi, it is highly likely that your email was leaked at some point in time. Someone has managed to grab or is scraping email lists that are related to Kodano users and are sending out these fake phishing scam emails. So please be careful, guys. Ignore all those emails.

Report them as spam and hopefully other people don’t get caught out by them either. The official communication channel is through the X account on EMURGO and SecondFi accounts only. So make sure you’re following the correct accounts here so you get the latest up to date news. I’ll be publishing as much as I can on X, on YouTube, on Reddit and on Facebook.

And so if you’re following any of those accounts on Kodano related stuff, you should see me appear and you should see all this information come out. So as soon as I find out when the brand new tool is up and running for for verifying if you’re being hacked or compromised and the migration process is all up as well. I’ll put all of them in a video and pack it out and then send it out to all the relevant channels as well. So guys, stay safe out there.

Most people that have been doing nothing or are already on hardware wallets are completely unaffected. So thankfully, a lot of people are still safe and haven’t interacted with SecondFi. So don’t need to worry about this too much. But still, there’s a lot of funds out there that have been compromised and hopefully we do see the funds return very soon.

Anyway, guys, if you found this video update useful, make sure you hit that thumbs up, like, subscribe, notification bell, YouTube memberships down below. I’ve got buy me a coffee links there as well. That’s a great way to support the channel and support the content and the work that I do in the Kodano ecosystem. And if you can’t do any of that, just make sure you hit that thumbs up on the way out.

Like always, guys, stay positive. I’ll see you in the next video.