SecondFi to shut down after $2.4 million ADA wallet theft
Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk
AI-assisted summary based on the linked source. Verify market-moving details at the original publisher before acting.
Cardano wallet provider SecondFi is shutting down following a software exploit that allowed attackers to steal 16.1 million ADA, approximately $2.4 million, from 374 wallets. The breach originated from a vulnerability in SecondFi’s transaction signing software, which enabled attackers to derive private keys from transaction data visible on the Cardano blockchain. Notably, the Cardano network itself was not compromised, and users who relied on hardware wallets were unaffected.
SecondFi, which had replaced EMURGO’s Yoroi wallet, had secured 129 million ADA at the time before the attackers could access those funds. Despite patching the vulnerability, SecondFi will not resume normal operations and is instead winding down. Groom Lake, a blockchain intelligence firm hired by EMURGO, described the primary attacker as sophisticated and well-funded, suggesting possible links to North Korea’s Lazarus Group, though no definitive attribution has been confirmed. Additionally, a separate attacker targeted other wallets in the same timeframe.
To assist affected users, SecondFi plans to release wallet export tools in early August and a zero-knowledge recovery portal later in the month. EMURGO has funded an asset recovery wallet to facilitate possible fund returns, but no firm timeline for distributions has been announced. This development underscores the risks associated with vulnerabilities in transaction signing software and the high stakes involved in cryptocurrency wallet security.