SecondFi to Shut Down After $2.4 Million ADA Wallet Theft

Cardano wallet SecondFi is on its way out after attackers exploited a flaw in its transaction signing software to steal 16.1 million ADA, worth around $2.4 million, from 374 wallets.

The service, which replaced EMURGO’s Yoroi wallet, said it would not resume normal operations despite patching the vulnerability and that it had at the time obtained 129 million ADA before the attackers could access the funds.

The flaw allowed attackers to derive private key elements from transaction data visible on the Cardano blockchain, SecondFi said. The Cardano network itself was not compromised and hardware wallet users were not affected.

Groom Lake, the blockchain intelligence firm hired by EMURGO, discovered that the main attacker was sophisticated and well-funded. Some indicators point to North Korea’s Lazarus Group, although no attribution has been confirmed, the company said.

Another attacker targeted another set of wallets during the same period.

SecondFi plans to release wallet export tools in early August and a zero-knowledge recovery portal later in the month. EMURGO has funded an asset recovery portfolio, but no firm distribution date has been communicated.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top