SecondFi, the Cardano ecosystem wallet formerly known as Yoroi, faces a loss estimate that dwarfs its own damage report. Blockchain security firm SlowMist founder Cos assessed potential losses at $20 million, according to a public statement. SecondFi had announced $2.4 million in damages roughly 13 hours after the exploit occurred.

The gap between the two figures signals either incomplete visibility into affected accounts or a significant undercount of the true scope. SlowMist's estimate carries weight in incident response circles, but the firm has not yet published a detailed forensic breakdown of how it arrived at the higher number. The methodology behind the $20 million assessment remains unclear from available sources.

SecondFi's initial disclosure came within a narrow window after the vulnerability was exploited, which typically limits the depth of damage assessment. Recovery efforts and compensation measures depend heavily on whether the platform can isolate the attack surface and confirm which wallets were compromised. The Cardano network itself was not affected; the breach targeted the wallet application layer.

Users who held funds in SecondFi during the exploit window face an extended period of uncertainty. Complete loss accounting often takes days or weeks as blockchain forensics teams trace transactions and identify funds moved off-exchange or into mixers. Platform recovery timelines hinge on whether developers can patch the vulnerability and restore confidence among users before further erosion of deposits occurs.

The discrepancy underscores a recurring friction point in crypto security incidents: initial damage reports often lack comprehensive data, and third-party auditors may reach materially different conclusions once they access transaction logs and user fund status. Cos's warning suggests the actual hit to the ecosystem may be substantially worse than SecondFi's own count indicated within hours of the breach.