- Cardano wallet SecondFi is shutting down after a software exploit allowed attackers to steal 16.1 million ADA ($2.4 million) from 374 wallets.
- The breach stemmed from a vulnerability in transaction signing software that enabled the derivation of private keys from blockchain transaction data.
- SecondFi will release wallet export tools in early August and a recovery portal later that month, though no distribution date for recovered funds is set.
Cardano wallet SecondFi is winding down after attackers exploited a flaw in its transaction signing software to steal 16.1 million ADA, worth roughly $2.4 million, from 374 wallets.
The service, which replaced EMURGO’s Yoroi wallet, said it will not resume normal operations despite patching the vulnerability.and at the time securing 129 million ADA before attackers could reach the funds.
The flaw allowed attackers to derive private key material from transaction data visible on the Cardano blockchain, SecondFi said. The Cardano network itself was not compromised, and hardware wallet users were not affected.
Groom Lake, the blockchain intelligence firm hired by EMURGO, found that the main attacker was sophisticated and well-funded. Some indicators point to North Korea’s Lazarus Group, though no attribution has been confirmed, the firm said.
A separate attacker targeted another set of wallets during the same period.
SecondFi expects to release wallet export tools in early August and a zero-knowledge recovery portal later that month. EMURGO has funded an asset recovery wallet, but no firm distribution date has been given.
0 Comments
Log in to join the conversation.No comments yet. Be the first to share your thoughts.