NewsCryptoSecondFi to Shut Down After $2.6M ADA Wallet Exploit Affects 374 Users

SecondFi to Shut Down After $2.6M ADA Wallet Exploit Affects 374 Users

Author: Cointelegraph·

Key Takeaways

  • The exploit affected 374 wallets and resulted in the theft of approximately 16.1 million ADA worth about $2.6 million.
  • SecondFi confirmed it will discontinue both its own wallet service and Yoroi following the breach.
  • Groom Lake identified a sophisticated external attacker and found possible Lazarus Group indicators, but no definitive attribution has been confirmed.
  • SecondFi is developing a zero-knowledge proof-based recovery tool that is expected to undergo third-party review before a planned August launch.
  • Affected users have criticized delays after SecondFi previously said it expected to begin recovery within about two weeks of its June 27 update.
SecondFi to Shut Down After $2.6M ADA Wallet Exploit Affects 374 Users

Cardano-based wallet provider SecondFi is winding down operations after a cryptographic flaw in its wallet software enabled attackers to steal approximately 16.1 million ADA, worth roughly $2.6 million, from users. The incident underscores the persistent security challenges facing self-custodial wallet infrastructure, where vulnerabilities in the software layer can compromise user funds even when private keys are not directly exposed to users.

In an update published on Wednesday, SecondFi confirmed that it will discontinue both SecondFi and Yoroi wallet services following the breach, which affected 374 wallets. The company first disclosed the exploit in late June. Yoroi, previously developed by EMURGO — one of Cardano's three founding entities — was one of the ecosystem's most widely used light wallets before its operations were transferred to SecondFi.

An independent investigation conducted by blockchain intelligence provider Groom Lake identified a sophisticated external actor as responsible for the attack. The investigation also uncovered indicators potentially associated with North Korea's Lazarus Group, though SecondFi noted that no definitive attribution has been confirmed. The Lazarus Group has been linked by United States authorities and multiple blockchain analytics firms to billions of dollars in cryptocurrency thefts, including major exchange and protocol exploits, making potential involvement in a wallet-layer attack a notable development.

Recovery Efforts Underway

SecondFi said it is developing a recovery tool based on zero-knowledge proofs designed to help affected users recover assets while minimizing the amount of information they must share. The tool remains in testing and will undergo review by a third-party auditor ahead of a planned release in August.

The platform is also preparing wallet export functionality to allow users to migrate assets to another service. SecondFi has not announced a direct reimbursement plan or indicated whether it would compensate users from its own funds. The decision to wind down rather than remediate in place contrasts with the approach taken by some other wallet and infrastructure providers that have suffered exploits, some of which have pursued token-funded reimbursement programs or insurance-backed recovery mechanisms.

Users Frustrated by Delays

The latest update has drawn criticism from affected users who say they are still waiting for a clear recovery path. On June 27, SecondFi stated it had identified a recovery approach and expected to begin the process within approximately two weeks, pending testing and security reviews. Nearly a month later, the company said the tool is still under development and now targeted for an August launch.

Earlier guidance from SecondFi advised impacted users not to restore recovery phrases into new Cardano wallets, warning that moving funds elsewhere "does not mitigate the risk" while the investigation was ongoing.

"But many of us were told our funds could be recovered within two weeks. Now we're being asked to wait even longer," one user wrote in response to the Wednesday update.

Cointelegraph contacted SecondFi for details on potential reimbursement plans but did not receive a response by publication time. EMURGO also did not respond to earlier requests for comment.

Related: Allbridge pauses cross-chain bridge after $1.65M exploit