Key Highlights
- SecondFi said a cryptographic flaw in transaction signature generation led to the theft of 16.1 million ADA ($2.6 million) from 374 wallets.
- An independent forensic investigation found the attack was carried out by a sophisticated external actor, with possible links to the Lazarus Group.
- The flaw has been patched, but SecondFi shuts down its platform and Yoroi wallet while preparing recovery and wallet migration tools.
SecondFi, a self-custody neofinance platform, has issued a detailed update on a security incident that occurred between June 21 and June 23, during which approximately 16.1 million ADA, valued at around $2.6 million, was stolen from 374 wallets. The company attributed the breach to a cryptographic flaw.
In an official update on X today, the company said it engaged Groom Lake, a blockchain intelligence provider, to commission an independent forensic investigation. The review examined code, code history, and public blockchain data.
What do the findings reveal
According to the findings, the primary unauthorized transfers were carried out by a sophisticated external actor using advanced methods. The operation appeared well-funded, with indicators potentially consistent with state-aligned threat activity, including possible links to the DPRK-associated Lazarus Group.
Investigators also identified a second party responsible for compromising a different set of wallets during the same period, with no overlap detected between the affected wallets so far.
The root cause of the incident was identified as a subtle cryptographic flaw in the wallet software’s method for generating per-transaction signatures. Under certain conditions, a value that should have remained secret could be derived from publicly visible transaction data on the blockchain.
This allowed attackers to reconstruct affected private key material. The same flaw was also present in an unauthorized copy of the relevant code that had been published on a public GitHub repository. SecondFi stated that it is continuing to assess how the code was made public and is cooperating with authorities.
What response did SecondFi take
In response, the cryptographic flaw has been patched. New wallets created with the updated software are not believed to be vulnerable. Despite this, SecondFi has decided to wind down both the SecondFi platform and the associated Yoroi wallet due to the severity of the breach.
A recovery tool using zero-knowledge proofs is under development and scheduled for release in August 2026 after third-party auditing. In the interim, wallet export functionality is expected by early August 2026 to allow users to migrate assets to wallets of their choice.
SecondFi emphasized that it will never request private keys, recovery phrases, or credentials and advised users to rely only on official channels for information.
Inadequate review process highlighted
This incident highlights shortcomings in SecondFi’s development and oversight practices. A cryptographic flaw in core wallet functionality suggests inadequate review processes, especially given its visibility in leaked code on GitHub.
The loss of $2.6 million from hundreds of users, combined with the decision to shut down the entire platform and Yoroi wallet, leaves many without continued service and raises questions about long-term accountability.
While investigators said the attack may have involved state-sponsored actors, that does not change the fact that the vulnerability enabled the theft. Affected users still face uncertainty during the recovery process, while the planned shutdown of the platform may limit long-term support options.
Also Read: Strategy’s MSTR and Bitcoin Show Tight Correlation in Price Recovery
