SecondFi, a provider once tasked with advancing Cardano’s Yoroi wallet, is shutting down after a glaring software vulnerability resulted in the theft of 16.1 million ADA, leaving 374 wallets compromised. The breach permitted intruders to derive private keys by exploiting blockchain transaction data, leading to unauthorized fund access.
What Went Wrong?
The security flaw was discovered in the transaction signing software, which inadequately protected sensitive key material. This loophole led to hackers reconstructing users’ private keys through transaction data on the Cardano blockchain, although the blockchain itself was not compromised. Users with hardware wallets remained secure thanks to their devices’ isolation capabilities.
Who Is Behind the Attack?
Investigations led by Groom Lake revealed that the key perpetrator showed exceptional skill and considerable resource access. Although there were hints of ties to North Korea’s Lazarus Group, a definitive link remains unconfirmed. Meanwhile, another assailant took advantage of the same lapse in security to target another set of wallets.
SecondFi quickly moved to shield 129 million ADA from being pilfered, though it’s halting further wallet operations despite rectifying the security issue.
“SecondFi underscored the breach as stemming from its transaction signing software weakness, but clarified that hardware wallet users were unaffected,” the company reported.
Tools for wallet export are set to be provided in August, allowing users to transfer their Cardano assets securely. This will be followed by a zero-knowledge recovery portal for safe retrieval without privacy loss.
While EMURGO, who initially developed Yoroi, has funded an asset recovery wallet, the timeline for the recuperation of lost ADA remains unspecified. Ongoing collaboration is essential to further counteract the breach’s repercussions.
- Cardano blockchain remained uncompromised by the breach.
- Hardware wallet users faced no risk from the technical flaw.
- Coordinated efforts ongoing to address the breaches comprehensively.
- Software wallet operations have permanently ceased.
With SecondFi’s closure, focus shifts towards restoring user trust and finalizing the process for affected users to reclaim their lost assets. Coordination among key players remains pivotal in mitigating the damage inflicted by the breach.



