Yoroi Wallet Shutdown (2026): What Happened and How to Move Your ADA
If you have ever used the Yoroi wallet — even years ago — this guide is for you. In July 2026, EMURGO permanently shut down Yoroi and its successor SecondFi after a security exploit drained over 16 million ADA from more than 370 wallets.
If you still hold funds in a Yoroi-created wallet, you need to know what happened, whether you are affected, and exactly how to move your money out safely. The Cardano network itself was never compromised — but the way to rescue your ADA has strict rules now. This guide walks through all of them, step by step.
What Was the Yoroi Wallet?
To understand what happened, you need to know what Yoroi was. What is Yoroi? Yoroi was a light wallet for Cardano — a browser extension and mobile app built by EMURGO, one of the three founding organizations of Cardano (alongside IOG and the Cardano Foundation). It launched in 2018 and for nearly eight years served more than a million users as Cardano's most popular self-custody wallet.
The Yoroi wallet extension ran in Chrome, Edge, and Firefox, letting you hold ADA, receive and send it, delegate to stake pools, and connect to dApps — all without downloading the full blockchain. A Yoroi light wallet was the opposite of a full node like Daedalus: it asked a server for your balance instead of validating the chain itself. That convenience made it the default recommendation for beginners and for people who did not want to run a node.
Key idea: Yoroi held your private keys on your own device — not on EMURGO's servers. Self-custody means you controlled the money. That is why this incident is about the wallet software, not about a server being hacked.
The old [Yoroi Cardano wallet] worked with a 15-word recovery phrase (BIP39 standard), supported Ledger and Trezor hardware wallets, and made staking one click. It was open source — the code was public on GitHub. Being open source did not save it: the exploit lived in a subtle flaw that took years and a rebrand to surface.
The 2026 Incident: What Happened?
Figure 1: Yoroi history to the shutdown — from 2018 launch to July 2026
Here is the timeline that matters:
- April 2026 — The rebrand. At Money20/20 in Bangkok, EMURGO rebranded Yoroi as SecondFi, a new "neofinance" platform. Same wallet technology, new name and vision.
- June 8, 2026 — The flaw ships. An Android app update introduced a defect in how the wallet created transaction signatures.
- June 21–23, 2026 — The exploit. Attackers drained 16.1 million ADA (~$2.4–2.6 million) from 374 wallets in four separate theft events. Forensic firm Groom Lake found indicators pointing to a sophisticated, well-funded actor with ties to the North Korean Lazarus Group — plus a second, separate attacker hitting a different set of wallets.
- July 6, 2026 — The shutdown. EMURGO announced SecondFi (and Yoroi) would never resume normal operations, even after audits. Its role was reduced to a dedicated asset-recovery team.
During the incident, EMURGO managed to secure about 129 million ADA in emergency containment — funds that were one step away from being drained. The company also funded an on-chain asset-recovery wallet to return stolen funds to victims.
The Technical Problem, in Plain Language
Figure 2: The signing flaw — public signatures let attackers reconstruct private keys
This part matters, because it changes what you can and cannot do next. Most crypto hacks happen when a device is compromised — malware steals your files. This was not that. No one hacked your phone.
The flaw was in how SecondFi's software built a digital signature for each transaction. In cryptography, a signature is supposed to prove "the owner of this private key approved this." The wallet was supposed to use a secret value when computing the signature. Under certain conditions, the software used a value that could be reconstructed from public data.
In plain terms: every transaction signed with the affected app published enough information on the public blockchain for an attacker to reconstruct the private key. The keys leaked to the blockchain — not to a breached server. That is why the exposure is permanent: the data is public forever, even after the app was patched and the platform shut down.
Critical: Because the private key itself leaked, restoring an affected seed phrase into any other wallet offers no protection. The attacker can already derive the key from the old on-chain signatures. Do not transfer an affected wallet by "restoring" its phrase into Lace, Eternl, or anything else — use the official recovery path described below.
Am I Affected?
Figure 3: Am I affected? Three paths to find out
The good news: this affected a specific set of 374 wallet addresses — not every Yoroi wallet. Here is how to know where you stand.
Path 1 — You used a hardware wallet (Ledger/Trezor). If you used Yoroi or SecondFi only as a viewing window for a Ledger or Trezor, you are not affected. The private key never left the hardware device, and signatures were created there, not in the app. No action needed.
Path 2 — You created wallets with Yoroi or SecondFi. Open the SecondFi app. It is now in quarantine mode: you can view your balance and your incident status, but transactions are disabled. If an address is potentially affected, a warning banner appears on your home screen. If you cannot open the app, use the official checker at checker.secondfi.io — the only legitimate one. It will never ask you to sign anything.
Path 3 — You are affected. You see the warning banner. Stop. Do not send, receive, sign, or stake from that wallet. Your funds may be eligible for recovery (more below), and touching the wallet could complicate the claim.
Scam warning for Vietnamese readers: after the shutdown, fake "SecondFi/Yoroi support" accounts are circulating on Facebook and Telegram, and fake "recovery" browser extensions exist. The official app never asks for your seed phrase or private key and never DMs you first. Any tool that asks you to "verify" by signing or entering your phrase is a scam. The only official channel is secondfi.io.
What to Do Now — Step by Step
Figure 4: What to do now — four steps for every former Yoroi user
Whatever your status, these rules apply to everyone who ever used Yoroi or SecondFi:
- Do not delete the SecondFi app. Recovery requires at least one of two things: the app, or your seed phrase. If you already deleted the app, your seed phrase is now the only way back — guard it like your life depends on it, because it does.
- Keep your seed phrase safe and offline. Never type it into any website, extension, or chat. The official recovery portal uses zero-knowledge proofs precisely so you never have to reveal it.
- Do not restore an affected wallet's phrase into another wallet. Repeating because it is the #1 mistake: if your address is on the affected list, restoring the phrase into any other wallet gives an attacker the same access. The exposure is in the public blockchain, not in the app.
- Wait for the official tools. Do not try to "rescue" funds by rushing transactions. The official export and recovery tools are built for exactly this.
The Recovery Roadmap — What Happens Next
Figure 5: The recovery roadmap — targets, not guarantees
EMURGO, with help from IOG and the Cardano Foundation, published a dated roadmap. Treat these as targets, not guarantees — dates have already slipped once.
| Stage | When (target) | What it does |
|---|---|---|
| Quarantine mode | Now | View balance + incident status only; no transactions |
| Wallet export tools | Early August | Let unaffected users securely migrate funds to a hardware wallet or alternative platform |
| Migration tool | Mid-August | Automated tool for users of all levels — unstakes ADA and transfers coins, tokens, and NFTs to a wallet you choose |
| ZK recovery portal | Early September | Zero-knowledge-proof portal for affected users to prove ownership and recover assets — without revealing the seed phrase. Requires a security audit first |
If you are affected: your drained assets will be returned through an on-chain asset-recovery wallet funded by EMURGO. The ZK portal is how you claim them. Until it launches, keep the app (or the phrase), do not touch the wallet, and watch official channels. If you have not already, submit a support ticket at support.secondfi.io.
If you are unaffected: you can move your funds as soon as the export tool (early August) or migration tool (mid-August) ships. If you have a technical background, the safest immediate option is migrating to a hardware wallet using the official guide.
What Should You Use Instead? Safe Alternatives
Figure 6: Safe alternatives — hardware wallets, Lace, Eternl, Daedalus
After the shutdown, the question every former Yoroi user asks is: where do I go? The good news is Cardano has strong options — and now you know to check who built them and how keys are handled.
- Hardware wallets (Ledger / Trezor). The most secure option. Your private keys never leave the device, and every transaction is confirmed on the hardware itself. The type of exploit that killed SecondFi cannot touch keys that never exist in software. Best for larger amounts.
- Lace (by IOG). The recommended default for beginners today — a light wallet from the Cardano development team itself, with browser and mobile apps. Our guide on setting up your first wallet walks through it step by step.
- Eternl. A feature-rich light wallet popular with power users (DeFi, NFTs), with Ledger/Trezor support.
- Daedalus. Cardano's official full-node wallet — maximum sovereignty at the cost of a heavy download. See our Daedalus guide for whether it fits you.
One honest note: if your old Yoroi wallet is not on the affected list, its seed phrase is a standard BIP39 phrase and restores fine into Lace, Eternl, or Daedalus — that part of the old advice still holds. The do-not-restore rule applies only to affected addresses, where the key already leaked publicly.
Security Lessons: Protect Yourself Going Forward
Figure 7: Seven security lessons from the Yoroi shutdown
The SecondFi incident is painful, but it teaches seven lessons that apply to every wallet you will ever use:
- Hardware wallets are worth it for real money. Keys that never touch software cannot be stolen from software.
- Know who builds your wallet. Open source is good, but audits and a track record matter more. Check the organization and its history.
- Your seed phrase is everything. In self-custody, no seed phrase = no money, no exceptions, no "recovery."
- Never type a seed phrase into a website. The ZK portal exists specifically so you do not have to.
- Use only official tools. During a recovery window, the fake tools and fake support are the biggest active threat.
- Never sign anything you do not understand. Legitimate tools never ask you to "verify" by signing from an affected wallet.
- Diversify. Holding everything in one wallet — or one ecosystem — concentrates risk. Split large holdings across hardware and a light wallet.
FAQ
Is the Yoroi wallet still working? No. EMURGO permanently shut down Yoroi and SecondFi in July 2026. The SecondFi app still opens in quarantine mode for checking balance and incident status, but transactions are disabled.
Is my ADA safe? If your wallet is not on the 374-address affected list, your funds are intact — the network was never compromised. If you are affected, drained assets are being returned through an EMURGO-funded recovery wallet, claimable via the ZK portal in early September.
Was all of Yoroi compromised? No. The incident affects a specific set of wallet addresses (374), not all Yoroi wallets. Hardware-wallet users were not affected at all.
Can I restore my Yoroi seed phrase into another wallet? Only if your address is not on the affected list. For affected addresses, restoring the phrase into any other wallet is dangerous — the private key already leaked to the public blockchain, so the attacker keeps the same access.
I deleted the SecondFi app. Can I still recover? Yes, if you still have your seed phrase — it is now the only way to claim. Recovery requires the app or the seed phrase.
How do I know if I'm affected? Open the SecondFi app and look for a warning banner, or use the official checker at checker.secondfi.io. Anything else claiming to check your status is a scam.
Was the Cardano network hacked? No. The network and the Cardano blockchain were never compromised. Only wallets created with the flawed signing software were at risk.
Quick Reference
| Question | Answer |
|---|---|
| What happened? | Signing flaw in SecondFi app leaked private keys to the public blockchain; 16.1M ADA stolen from 374 wallets |
| Status now | SecondFi + Yoroi permanently shut down (July 2026); app in quarantine mode |
| Affected? | Check the app banner or checker.secondfi.io — only 374 specific addresses |
| Hardware wallet users | Not affected — no action |
| Top rule | Do NOT restore an affected seed phrase into any other wallet |
| Keep | The SecondFi app AND your seed phrase |
| Export tools | Early August (unaffected users) |
| Migration tool | Mid-August (all users) |
| ZK recovery portal | Early September (affected users) |
| Safe alternatives | Ledger/Trezor, Lace, Eternl, Daedalus |
Updated: 2026-08-09 | Written by VCC Content Team — Cardano educators since 2021 | Technical review: [Cardano SPO/Developer] | Sources: SecondFi official KB, EMURGO statements, CoinDesk, Cointelegraph, The Defiant, TechTimes | Recovery timeline is subject to change — verify on secondfi.io.
