SecondFi to shut down after $2.4 million ADA wallet theft
CoinDesk 2026-07-22 11:10:27
Context: SecondFi, a Cardano wallet service, is shutting down after a software exploit allowed attackers to steal 16.1 million ADA, worth approximately $2.4 million, from 374 wallets. The breach resulted from a vulnerability in transaction signing software that enabled the derivation of private keys from blockchain transaction data. SecondFi will release wallet export tools and a recovery portal, but no distribution date for recovered funds has been set.
Key Facts
- SecondFi was exploited for 16.1 million ADA, worth roughly $2.4 million, from 374 wallets due to a vulnerability in its transaction signing software.
- The flaw allowed attackers to derive private key material from transaction data visible on the Cardano blockchain, without compromising the Cardano network or affecting hardware wallet users.
- SecondFi secured 129 million ADA before attackers could reach the funds, and a separate attacker targeted another set of wallets during the same period.
- Groom Lake, a blockchain intelligence firm, found that the main attacker was sophisticated and well-funded, with indicators potentially pointing to North Korea's Lazarus Group, although no attribution has been confirmed.
- SecondFi plans to release wallet export tools in early August and a zero-knowledge recovery portal later that month, with EMURGO funding an asset recovery wallet, but no firm distribution date for recovered funds has been given.