TL;DR
-
SecondFi is winding down operations after a security breach resulted in the theft of 16.1 million ADA (approximately $2.4 million) from 374 wallets.
-
Attackers exploited a flaw in the wallet's transaction signing software, not the Cardano blockchain itself.
-
Blockchain intelligence firm Groom Lake said the primary attacker appeared highly sophisticated, with some indicators pointing to North Korea's Lazarus Group, though attribution remains unconfirmed.
Cardano wallet provider SecondFi has announced it will shut down after a security vulnerability in its transaction signing software enabled attackers to steal 16.1 million ADA, valued at approximately $2.4 million, from 374 user wallets.
The wallet service, which succeeded EMURGO's Yoroi wallet, said it has fixed the vulnerability but will not resume normal operations, opting instead to focus on helping affected users recover their assets.
Vulnerability Exposed Private Key Material
According to SecondFi, the exploit stemmed from a flaw in its transaction signing implementation.
The vulnerability allowed attackers to derive private key material from transaction information that was publicly visible on the Cardano blockchain. With access to this information, the attackers were able to compromise affected wallets and steal users' funds.
The company emphasized that the Cardano blockchain itself was not breached and that users who stored their assets with hardware wallets were not impacted by the attack.
The exploit resulted in the theft of 16.1 million ADA across 374 compromised wallets. SecondFi said it managed to secure an additional 129 million ADA before the attackers could access those funds, limiting the overall impact of the breach.
The company has not disclosed whether any of the stolen assets have been recovered.
Investigators Examine Possible Lazarus Group Links
EMURGO enlisted blockchain intelligence firm Groom Lake to investigate the incident. According to the firm's preliminary findings, the primary attacker demonstrated a high level of sophistication and appeared to have significant financial and technical resources.
Investigators noted that some indicators resemble tactics associated with North Korea's Lazarus Group, a state-linked hacking organization responsible for several major cryptocurrency thefts. However, Groom Lake stressed that no definitive attribution has been made.
The investigation also identified a second attacker who targeted a different group of wallets during the same period.
Although SecondFi is discontinuing its wallet service, the company says it is continuing to develop tools to help users regain access to their remaining assets.
The roadmap includes:
-
Wallet export tools scheduled for release in early August.
-
A zero-knowledge recovery portal expected later in the month.
-
An asset recovery wallet funded by EMURGO to assist victims.
While EMURGO has committed resources to the recovery effort, the companies have not announced a timeline for distributing recovered assets.
Cardano Network Remains Secure
The incident highlights the distinction between vulnerabilities in third-party wallet software and the underlying blockchain network.
SecondFi reiterated that the exploit was limited to its wallet implementation and did not affect Cardano's consensus mechanism or blockchain infrastructure. Hardware wallet users also remained protected because their private keys never left their secure devices.
Hassan Maishera