SecondFi to shut down after $2.4 million ADA wallet theft

SecondFi is shutting down operations following a $2.4 million theft of ADA tokens from its wallet service. While the vulnerability has been patched, the company is focusing on asset recovery and providing export tools for users.
Why it matters
The incident underscores the persistent security risks in decentralized finance and the potential involvement of state-sponsored actors in crypto-asset theft.
The service, which replaced EMURGO’s Yoroi wallet, said it will not resume normal operations despite patching the vulnerability.and at the time securing 129 million ADA before attackers could reach the funds.
The flaw allowed attackers to derive private key material from transaction data visible on the Cardano blockchain, SecondFi said . The Cardano network itself was not compromised, and hardware wallet users were not affected.
Groom Lake, the blockchain intelligence firm hired by EMURGO, found that the main attacker was sophisticated and well-funded. Some indicators point to North Korea’s Lazarus Group, though no attribution has been confirmed, the firm said.
A separate attacker targeted another set of wallets during the same period.
SecondFi expects to release wallet export tools in early August and a zero-knowledge recovery portal later that month. EMURGO has funded an asset recovery wallet, but no firm distribution date has been given.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in