SecondFi to Shutdown After $2.6M ADA Theft Exposes Critical Wallet Flaw

SecondFi to Shutdown After $2.6M ADA Theft Exposes Critical Wallet Flaw
Table of Contents

TL;DR

  • SecondFi will shut down its services after the theft of 16.1 million ADA, equivalent to approximately $2.6 million, due to a cryptographic flaw in its software.
  • The Groom Lake investigation identified a sophisticated attacker with indicators potentially linked to North Korea’s Lazarus Group.
  • Recovery tools based on zero-knowledge proofs were expected within two weeks and are now scheduled for August.

SecondFi announced the closure of its operations after an exploit exposed a critical vulnerability in its wallet software and resulted in the theft of approximately 16.1 million ADA, valued at around $2.6 million. The platform, built on the Cardano network, confirmed the shutdown through an official statement nearly a month after the initial disclosure of the incident, which occurred in late June.

According to the statement, the attack affected 374 wallets and was executed through a cryptographic flaw in SecondFi’s own software. The company commissioned an independent investigation from Groom Lake, a blockchain intelligence provider, whose findings identified a sophisticated external actor behind the attack. The report also flagged indicators potentially linked to the Lazarus Group, the cyberattack collective attributed to North Korea, although the company clarified that no formal attribution has been confirmed.

SecondFi Remains in Recovery Process

Since the exploit was disclosed, SecondFi instructed affected users not to restore their recovery phrases in new Cardano wallets. The platform argued that moving funds to another service “does not mitigate the risk” while the internal investigation continued. On June 27, the company communicated that it had identified a recovery path and estimated the process would begin in approximately two weeks, once security testing and reviews were completed.

SecondFi divulgó una brecha en su software de generación de wallets

Nearly a month later, that deadline was not met. The recovery tool, based on zero-knowledge proofs, remains under development and must undergo external auditor review before its launch, which is now scheduled for August. The platform is also working on a wallet export feature that will allow users to migrate their assets to another service.

What SecondFi did not announce is a direct reimbursement plan or any compensation mechanism using its own funds. The protocol did not respond to inquiries regarding potential indemnification plans. EMURGO, the organization linked to the Cardano ecosystem, also did not respond to requests for comment.

Hacker

User Frustration

The latest update drew critical reactions from those affected. “But many of us were told our funds could be recovered within two weeks. Now they’re asking us to wait even longer,” wrote one user in response to the official statement.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews