SecondFi shuts down after $2.6M ADA theft
SecondFi, the Cardano wallet provider that replaced Yoroi, is winding down after a breach stole about 16.1 million ADA from 374 wallets, worth roughly $2.4–$2.6 million. The attack exploited a flaw in SecondFi’s transaction signing software, enabling private keys to be derived from on-chain transaction data, while the Cardano network itself remained unaffected. EMURGO and SecondFi say they were able to secure a large portion of funds (around 129 million ADA) through recovery efforts, but a verified path to reimburse affected users has not been established. The company is shifting from a growth narrative to recovery operations, planning August releases of wallet export tools and a zero-knowledge recovery portal to help users migrate or recover assets. Investigations by Groom Lake describe the attacker as sophisticated, with some indicators pointing to Lazarus Group, though attribution has not been confirmed. EMURGO emphasizes that the breach was a software-layer issue, not a Base Layer protocol flaw, and hardware wallets were not exposed.
Ask this story anything
How it spread

