SecondFi Shuts Down After $2.4 Million ADA Wallet Theft

Cardano wallet SecondFi is winding down after attackers exploited a flaw in its transaction signing software to steal 16.1 million ADA, worth about $2.4 million, from 374 wallets.

The service, which replaced EMURGO’s Yoroi wallet, said it will not resume normal operations despite the vulnerability being patched.

The flaw allowed attackers to derive private key material from transaction data visible on the Cardano blockchain, SecondFi said. The Cardano network itself was not compromised and hardware wallet users were not affected.

Groom Lake, the blockchain intelligence firm hired by EMURGO, found that the main attacker was sophisticated and well-funded. Some indicators point to North Korea’s Lazarus Group, although no attribution has been confirmed, the firm said.

A separate attacker targeted another set of wallets during the same period.

SecondFi expects to release wallet export tools in early August and a zero-knowledge recovery portal later that month. EMURGO has funded an asset recovery wallet, but no firm distribution date has been given.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top