SecondFi has issued a security alert warning users about a SecondFi phishing scam circulating through email. The message claims to be an official recovery notice but is designed to trick people into handing over control of their wallets.

Source: X post
According to SecondFi, the phishing email tells recipients to enter a so-called "Quarantine Mode" and sign a Service Agreement in order to recover their assets, warning that funds will be lost if they don't act. SecondFi has confirmed this is entirely false. There is no such agreement in place, and no recovery process ever requires a user to sign anything.
SecondFi states the only legitimate action right now is submitting a support ticket. Any message asking for more than checking a wallet and filing a ticket should be treated as a scam. The company reiterated that it will never request a recovery phrase, private keys, or wallet credentials and will never message or email users first. It has urged people not to click the link in the fraudulent email or sign or approve anything it leads to.
This SecondFi phishing scam is emerging in the aftermath of a real security breach. SecondFi, the Cardano wallet platform formerly known as Yoroi, was hit by a wallet-generation vulnerability that exposed user funds.
SecondFi's own initial estimate placed losses at roughly 16 million ADA, while blockchain security firm SlowMist put the figure far higher, tracing more than 129 million ADA and other tokens through wallets linked to the attacker. That gap between the two estimates has left the full scale of the breach unresolved pending an independent audit.
The exploit added to a string of infrastructure-layer attacks that gained pace through 2026, following incidents like Humanity Protocol's private key breach and the Syscoin bridge exploit.
Cardano founder Charles Hoskinson acknowledged the incident directly, noting that while the dollar losses may look small next to other crypto hacks, that offers no comfort to users who may have lost their entire ADA holdings. With no reimbursement timeline announced, scammers appear to be exploiting the confusion and anxiety among affected users, which is likely what triggered this latest phishing scam warning.
SecondFi's alert is a reminder that hacks rarely end when the exploit itself is patched. The aftermath often becomes fertile ground for a second wave of scams targeting confused and frightened users. A pattern also seen in similar phishing scams that have hit other major platforms. Anyone who held funds on the platform should verify any communication only through SecondFi's official channels and avoid signing anything sent through email, no matter how urgent it sounds.
This article is for educational and informational purposes only and should not be considered financial or investment advice. Always conduct your own research before making investment decisions.