CardanoScope Research
URGENT: A Malware Campaign Is Hijacking Crypto Wallets During Yoroi's Transition to SecondFi — Cold Storage Isn't Optional Anymore
shelley · security · 2026-06-23
cardano wallet-security secondfi yoroi cold-wallet malware hardware-wallet
SecondFi has confirmed a security issue directly. In a post on X, the SecondFi team said: "We identified a security issue impacting a small number of Cardano wallets on our platform. We have contained the issue and paused the affected functions. Our engineering teams are actively working to restore full functionality." The platform has entered maintenance mode with front-end interactions suspended. SecondFi hasn't specified the technical root cause, the exact number of wallets affected, or whether any funds were lost.
Separately, and on a wider scale than just SecondFi: Check Point Research published a report on June 3 documenting an active malware distribution campaign that targets a long list of wallet extensions — Yoroi, the Cardano wallet now rebranding as SecondFi, is named explicitly on that list, alongside MetaMask, Trust Wallet, Phantom, Coinbase Wallet, UniSat, and over a dozen others.
How the malware campaign works
The infection chain starts with fake download pages impersonating reverse-engineering tools — Ghidra, dnSpy, ILSpy — that rank highly in search and look professionally legitimate. The download button is rigged with click-hijacking JavaScript: your first click gets silently redirected through a Traffic Distribution System that fingerprints your browser, geography, and VPN status before deciding what to serve you. Depending on that routing, victims end up with one of several payloads, including two that matter here:
- RemusStealer, an infostealer that scans the infected machine for data belonging to a wide range of wallet extensions — Yoroi (Cardano) is on that target list, alongside roughly fifteen other wallets across multiple chains. It targets whatever wallet software happens to be installed on the infected machine, not Yoroi/SecondFi specifically.
- AnimateClipper, a clipboard hijacker. This is the one I'd weight most heavily for Cardano users: it continuously monitors your clipboard, recognizes wallet-address formats, and silently swaps any address you copy for one of several attacker-controlled addresses. You copy a real destination address, paste what you think is the same string, and the funds go to the attacker instead.
Check Point traces SessionGate (the installer framework behind this) back to August 2025, with active distribution from January 2026 onward, and on-chain activity from AnimateClipper-linked addresses going back to July 12, 2025. The report describes the embedded wallets as having received "real funds" but calls the observed inflows "modest" — no large confirmed loss figure is attached to this campaign.
A commentary piece on ainvest.com makes a structural point worth crediting directly: Yoroi's rebrand into SecondFi — new download paths, a new name, an expanded feature set covering spending, earning, swapping, and cross-chain movement — widens the window for impersonation and confusion, independent of whatever SecondFi's own engineering team finds in their current investigation. New brand names and new official links are exactly the kind of ambiguity a search-ranked fake download page is built to exploit.
What's still unknown
Neither SecondFi's statement nor Check Point's report gives a technical root cause, an exact count of affected wallets, or a loss figure. SecondFi hasn't published any of those numbers as of this writing.
One specific claim is circulating in Cardano's community: Bullish Dumpling饺子, a prominent Cardano DRep, posted that the team's preliminary estimate is around 16 million ADA stolen, with the vulnerability concentrated specifically in SecondFi's web-based wallet creation and mnemonic generation flow — wallets created or re-generated through SecondFi's website, not the Cardano chain itself, and not old Yoroi wallets that kept their original mnemonic without regenerating through the new web flow. I'm citing this because of who's saying it, not because I've independently verified it: I found no confirmation of either the 16 million ADA figure or this specific mechanism from SecondFi, Check Point, or any other source as of publishing. Treat it as the most specific account available right now, not as confirmed fact.
What's solid regardless: SecondFi has a confirmed, contained issue on their platform right now, and a documented malware campaign is separately and actively targeting Yoroi/SecondFi users' machines. Any one of these would be reason enough to act.
Why cold storage is the fix regardless of which cause applies to you
Malware on your machine or a flaw on SecondFi's own side lead to the same fix: your private key has to stay off any software that touches the internet. A hardware wallet signs transactions on a separate device, so neither vector can reach your keys.
Concretely, against AnimateClipper: a properly used hardware wallet displays the actual destination address on its own screen before you approve a transaction, so a clipboard-swapped address shows up as a mismatch you can catch — but only if you actually look. The device protects you; it doesn't protect you from not checking it. That habit has to come with the hardware, not as a footnote.
Against an infostealer like RemusStealer: there's nothing on the infected machine for it to steal if the private key was never generated or stored there in the first place. A browser-extension or app wallet, Yoroi/SecondFi or otherwise, keeps key material on the same general-purpose computer the malware is running on. A hardware wallet doesn't.
This isn't a verdict on SecondFi as a product, and it isn't investment advice — I'm not telling anyone what to hold or when. It's a statement about custody architecture: hot wallets on general-purpose computers are exposed to a malware category that's documented, active, and not going away, and a platform-side issue confirmed the same day only adds to the case. If you have funds sitting in a SecondFi/Yoroi hot wallet, this maintenance window is the moment to move anything you can't afford to lose into cold storage.
Andreas Antonopoulos didn't coin "not your keys, not your crypto" for this exact scenario, but it fits it precisely. The phrase is usually aimed at custodial exchanges. The version that applies here is the same logic one layer down: if your private key sits on a machine that anything else can read, you don't fully control it either — custody isn't just "do you hold the key," it's "does anything else have access to the same device that holds it." A hardware wallet is the practical answer to that second question.
--- Sources:
- SecondFi security update post — SecondFi (@secondfiapp) on X, 2026-06-23
- Community post on the SecondFi incident — Bullish Dumpling饺子, Cardano DRep, 2026-06-23
- Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem — Check Point Research, 2026-06-03
- SecondFi's security problems are not a new story. They are an old one with a new brand. — AInvest
- Yoroi Wallet Is Evolving Into SecondFi: What You Need to Know — Cardano.org, 2026-04-22
https://cardanoscope.com/reports/2026-06-23-shelley-urgent-yoroi-secondfi-wallet-malware