SecondFi shuts down after $2.6M ADA theft, users await recovery
SecondFi is shutting down after a wallet flaw led to the theft of up to $2.6M in ADA. Services will be discontinued, and users are frustrated by delays in recovery tools and lack of transparency.
SecondFi, a Cardano wallet provider, is shutting down after a major security breach resulted in the theft of approximately 16.1 million ADA—worth between $2.4 million and $2.6 million—from 374 user wallets. The breach was caused by a cryptographic flaw in the wallet’s transaction signing software, allowing attackers to derive private keys from public blockchain data. Investigations identified at least two attackers, with one displaying advanced techniques and possible links to the Lazarus Group, though no definitive attribution has been made. SecondFi managed to secure 129 million ADA before further losses occurred. The vulnerability has since been fixed, and new wallets with the patched software are reportedly secure. Despite these efforts, SecondFi and Yoroi wallet services will be discontinued. While the company promised recovery tools and wallet export features, users have expressed frustration over delays and a lack of transparency. Notably, the Cardano blockchain itself and hardware wallet users were not affected by the breach.