Key highlights:

  • SecondFi will wind down operations after a security flaw led to the theft of approximately 161 million ADA  worth $2.6 million from 374 wallets.
  • An independent investigation linked the primary attack to a sophisticated external threat actor, with indicators suggesting possible overlap with activity associated with North Korea's Lazarus Group.
  • Developers have patched the vulnerability and are preparing recovery and migration tools for affected users.

SecondFi, a Cardano-based wallet platform, has announced it will permanently shut down following a security breach that resulted in the theft of approximately 161 million ADA, valued at around $2.6 million, from 374 user wallets.

The company disclosed that the incident occurred between June 21 and June 23, with an independent forensic investigation concluding that the exploit stemmed from a previously undiscovered cryptographic vulnerability in the wallet's transaction-signing mechanism. Although the flaw has since been patched, SecondFi said the severity of the breach has made continuing operations untenable.

The announcement marks one of the most significant wallet security incidents within the Cardano ecosystem this year.

Investigation points to sophisticated external attackers

According to SecondFi, blockchain intelligence firm Groom Lake was engaged by Cardano development company EMURGO to conduct an independent forensic investigation into the attack.

The investigation found that the primary breach was carried out by a highly sophisticated external threat actor employing advanced operational techniques. Investigators said several indicators showed similarities with activity previously associated with the DPRK-linked Lazarus Group, though attribution remains under assessment and has not been conclusively confirmed.

The report also identified evidence of a second, unrelated attacker operating during the same period. Investigators noted that this secondary campaign targeted a different set of wallets and showed no overlap with victims affected by the primary exploit.

The findings were based on technical evidence, including code reviews, software history and publicly available blockchain transaction data.

Wallet flaw exposed private key material

SecondFi revealed that the root cause was a subtle cryptographic flaw in the wallet's implementation of per-transaction signatures.

Under specific conditions, values that should have been generated using secure internal randomness could instead be derived from publicly available transaction information recorded on the blockchain. This weakness potentially allowed attackers to reconstruct portions of users' private key material, ultimately enabling unauthorized transfers from affected wallets.

The company also disclosed that vulnerable portions of the code had previously appeared in an unauthorized public GitHub repository. Investigators are continuing to examine the circumstances surrounding that publication while cooperating with relevant authorities.

Developers confirmed that the vulnerability has now been patched, and newly created wallets using the corrected software are not believed to be susceptible to the same exploit.

Recovery efforts begin as SecondFi winds down

Despite resolving the software vulnerability, SecondFi said it has decided to discontinue both SecondFi and its Yoroi wallet operations due to the magnitude of the incident and its impact on user confidence.

The company said its immediate priority is assisting affected users through asset recovery efforts and providing secure migration options.

A zero-knowledge proof (ZK)-based recovery tool is currently under development to help users begin the recovery process while minimizing the amount of sensitive information required. The recovery system remains in testing and will undergo an independent third-party audit before its anticipated release in August 2026.

In parallel, SecondFi is preparing a wallet export feature that will allow users to migrate their remaining assets to alternative wallets. That migration functionality is expected to become available by early August.

The incident highlights the growing sophistication of attacks targeting crypto infrastructure. While smart contract exploits often dominate headlines, the SecondFi breach demonstrates that vulnerabilities within wallet software itself remain a critical security risk for users and developers alike.