SecondFi Phishing Scam Alert: Fake Recovery Emails Target Users

20-Jul-2026 CoinGabbar

SecondFi Warns Users of Fake Recovery Email Scam

SecondFi has issued a security alert warning users about a SecondFi phishing scam circulating through email. The message claims to be an official recovery notice but is designed to trick people into handing over control of their wallets.

SecondFi Warns Users of Fake Recovery Email Scam

Source: X post

What the Fake Email Says

According to SecondFi, the phishing email tells recipients to enter a so-called "Quarantine Mode" and sign a Service Agreement in order to recover their assets, warning that funds will be lost if they don't act. SecondFi has confirmed this is entirely false. There is no such agreement in place, and no recovery process ever requires a user to sign anything.

How SecondFi Says Users Should Respond

SecondFi states the only legitimate action right now is submitting a support ticket. Any message asking for more than checking a wallet and filing a ticket should be treated as a scam. The company reiterated that it will never request a recovery phrase, private keys, or wallet credentials and will never message or email users first. It has urged people not to click the link in the fraudulent email or sign or approve anything it leads to.

The Hack Behind the Warning

This SecondFi phishing scam is emerging in the aftermath of a real security breach. SecondFi, the Cardano wallet platform formerly known as Yoroi, was hit by a wallet-generation vulnerability that exposed user funds. 

SecondFi's own initial estimate placed losses at roughly 16 million ADA, while blockchain security firm SlowMist put the figure far higher, tracing more than 129 million ADA and other tokens through wallets linked to the attacker. That gap between the two estimates has left the full scale of the breach unresolved pending an independent audit.

Fallout Across the Market

The exploit added to a string of infrastructure-layer attacks that gained pace through 2026, following incidents like Humanity Protocol's private key breach and the Syscoin bridge exploit. 

Cardano founder Charles Hoskinson acknowledged the incident directly, noting that while the dollar losses may look small next to other crypto hacks, that offers no comfort to users who may have lost their entire ADA holdings. With no reimbursement timeline announced, scammers appear to be exploiting the confusion and anxiety among affected users, which is likely what triggered this latest phishing scam warning.

Conclusion

SecondFi's alert is a reminder that hacks rarely end when the exploit itself is patched. The aftermath often becomes fertile ground for a second wave of scams targeting confused and frightened users. A pattern also seen in similar phishing scams that have hit other major platforms. Anyone who held funds on the platform should verify any communication only through SecondFi's official channels and avoid signing anything sent through email, no matter how urgent it sounds.

Disclaimer 

This article is for educational and informational purposes only and should not be considered financial or investment advice. Always conduct your own research before making investment decisions.

Also read: Bitcoin News Today: BIP 110 Explained, Saylor Slams It as a Bad Idea
WHAT'S YOUR OPINION?
Related News