
The Cardano wallet provider said 16.1 million ADA was stolen through a flaw in transaction signature generation, while export and recovery tools are still expected in August.
SecondFi is winding down after attackers exploited a cryptographic flaw in transaction signature generation to steal 16.1 million ADA, worth about $2.6 million, from 374 wallets between June 21 and June 23. The company said the flaw has been patched and that new wallets created with updated software are not believed to be vulnerable, but it will still shut down both the SecondFi platform and the associated Yoroi wallet because of the severity of the breach. Groom Lake, the blockchain intelligence provider that conducted an independent forensic investigation, said the main unauthorized transfers were carried out by a sophisticated external actor and that some indicators were potentially consistent with DPRK-linked Lazarus Group activity, though no conclusive attribution was stated. Investigators also identified a second party that compromised a different set of wallets during the same period. SecondFi said the flaw allowed attackers to derive secret key material from publicly visible blockchain data under certain conditions, and said the same weakness was present in an unauthorized copy of the relevant code posted on a public GitHub repository. Wallet export tools are expected in early August 2026, with a zero-knowledge proofs-based recovery tool planned for later in August after a third-party audit, while the company said it is cooperating with authorities.