Cardano wallet SecondFi is shutting down after a flaw in its transaction signing software let attackers derive private keys from on-chain transaction data and steal 16.1 million ADA, worth roughly $2.4 million, from 374 wallets. The service, which replaced EMURGO's Yoroi wallet, said it will not resume normal operations despite patching the vulnerability. EMURGO said it raced to drain 129 million ADA from exposed addresses before attackers could reach them.
The Cardano network itself was not compromised, and hardware wallet users were not affected. The exploit instead lived in SecondFi's signing layer, where transaction data visible on-chain could be reverse-engineered to recover private key material. Groom Lake, the blockchain intelligence firm hired by EMURGO, found the main attacker was sophisticated and well-funded, with some indicators pointing to North Korea's Lazarus Group, though no attribution has been confirmed. A separate attacker targeted another set of wallets during the same period.
Why it matters
The kill chain is unusual: rather than phishing users or compromising a node, the attacker extracted private keys from public blockchain data, a class of flaw that turns every signed transaction into a slow-motion key recovery. Killing the wallet outright, rather than patching in place, signals EMURGO judged the trust damage irreversible once user key material had been exposed in bulk. The Lazarus-adjacent indicators also fold SecondFi into the broader pattern of state-aligned actors chasing wallet-layer weak points across non-Bitcoin ecosystems.
Market impact
SecondFi plans to release wallet export tools in early August and a zero-knowledge recovery portal later that month, giving users a path to move funds to new wallets. EMURGO has funded an asset recovery wallet, but no firm distribution date has been set, leaving 374 affected users in limbo on restitution. The reputational hit lands on EMURGO's wallet stack rather than on ADA itself, but it adds pressure on Cardano's wallet ecosystem to audit signing libraries and tighten public-data exposure for any client that handles user keys.
Frequently asked questions
-
What happened to SecondFi?
SecondFi is shutting down after a flaw in its transaction signing software let attackers derive private keys from on-chain transaction data and steal 16.1 million ADA, roughly $2.4 million, from 374 wallets. EMURGO said it will not resume normal operations despite patching the vulnerability.
-
Was the Cardano network itself hacked?
No. The Cardano network was not compromised. The exploit lived in SecondFi's signing layer, where public transaction data could be reverse-engineered to recover private key material. Hardware wallet users were not affected.
-
Who is blamed for the SecondFi attack?
Blockchain intelligence firm Groom Lake said the main attacker was sophisticated and well-funded, with some indicators pointing to North Korea's Lazarus Group. No attribution has been confirmed, and a separate attacker targeted another set of wallets during the same period.
-
What is SecondFi doing for affected users?
SecondFi plans to release wallet export tools in early August and a zero-knowledge recovery portal later that month. EMURGO has funded an asset recovery wallet, but no firm distribution date has been set for recovered funds.
-
How much ADA did EMURGO save during the incident?
EMURGO said it raced to drain 129 million ADA from exposed addresses before attackers could reach them, beyond the 16.1 million ADA already stolen from 374 wallets.
CoinDesk