Cardano Wallet Provider SecondFi Shuts Down Following $2.6 Million ADA Theft

A secondary attacker targeted a separate set of wallets during the same breach period, indicating multiple waves of exploitation beyond the initial 374 affected accounts.
SecondFi plans to release wallet export tools in early August and a zero-knowledge recovery portal later in August to help users migrate or recover assets, with the portal undergoing third-party auditing before release.
EMURGO has funded an asset recovery wallet to support the broader recovery effort, underscoring a dedicated effort beyond simply patching the software flaw.
EMURGO has not yet published a full technical audit of the incident, leaving questions about whether the breach was an isolated software flaw or indicative of broader design weaknesses.
SecondFi, the Cardano wallet that replaced Yoroi, is shutting down after attackers stole roughly 16.1 million ADA — worth about $2.4 to $2.6 million — from 374 wallets between June 21 and June 23, according to CryptoTimes and Decrypt. The company is now pivoting from growth to damage control.
The Cardano network itself was not touched. The flaw lived entirely in SecondFi's own software, which let attackers derive private keys from publicly visible transaction data on the blockchain.
The breach came down to one critical bug. SecondFi's transaction signing software generated keys in a way that allowed an attacker to reverse-engineer a user's private key just by looking at on-chain transaction data, according to CoinCodex. That data is public by design — which made the flaw especially dangerous.
EMURGO, SecondFi's developer, was quick to stress the separation. The breach was a software-layer issue, not a flaw in the Cardano base protocol. Hardware wallet users were not exposed. The company hired external security firm Groom Lake to investigate the incident, according to Cryptopolitan.
The attack did not stop with the first wave. A secondary attacker targeted a separate set of wallets during the same breach window, pointing to multiple rounds of exploitation beyond the originally confirmed 374 accounts, according to CryptoTimes.
Investigators at Groom Lake described the attacker as sophisticated. Some indicators point to North Korea's Lazarus Group, though Decrypt notes that attribution has not been confirmed. Lazarus has been linked to some of the largest crypto thefts in history.
EMURGO and SecondFi say they secured roughly 129 million ADA through recovery efforts — far more than the 16.1 million stolen. EMURGO set up a dedicated asset recovery wallet to support the broader effort, according to PYMNTS. But a verified path to reimburse affected users has not yet been established.
No full technical audit has been published. That leaves open questions about whether the bug was a one-off coding mistake or a sign of deeper design problems in the platform's architecture.
SecondFi is not disappearing overnight. The company plans to release wallet export tools in early August so users can move their assets to other wallets, according to Cryptopolitan. A zero-knowledge recovery portal — a privacy-preserving tool to help users recover assets without exposing sensitive data — is planned for later in August.
That portal will go through a third-party audit before it launches. The company says it is focused entirely on recovery operations now, not growth. No timeline for user reimbursement has been confirmed, and EMURGO has not said whether it will cover losses directly.
Publishers
12
Articles
7
Reach
19