SecondFi Reveals Cause of $2.6M ADA Breach as ZK Recovery Tool Nears Launch

ADA1.94%
  • SecondFi traced its loss of $2.6 million of ADA to a cryptographic flaw signature in the wallet software used by advanced external attackers in 374 wallets.
  • The company remediated the vulnerability, released recovery measures, and revealed its intentions to close SecondFi and Yoroi wallet offerings.

SecondFi opened up on the security incident which resulted in the loss of approximately 16.1 million of ADA. TAttackers stole approximately 16.1 million ADA, worth around $2.6 million, from 374 wallets between June 21 and June 23. SecondFi conducted an independent forensic investigation while continuing with their recovery operations and analysis of the technical details

An update regarding the recent security incident involving SecondFi

What happened to SecondFi
Between June 21st and 23rd, SecondFi experienced a security incident that resulted in approximately 16.1 million ADA (~$2.6 million) being stolen from 374 wallets. We want to provide…

— SecondFi (@secondfiapp) July 22, 2026

EMURGO engaged blockchain intelligence company Groom Lake to analyze blockchain activity, software code, and development history. Investigators determined that a well-resourced and sophisticated external threat actor carried out the attack. They were exploiting a cryptographic weakness in the wallet software Groom Lake also identified indicators that investigators are analyzing for possible links to the Lazarus Group. Moreover, investigators were able to determine the presence of the second, unrelated attacker.

Investigation Uncovers Cryptographic Flaw

The investigation identified a subtle vulnerability in the way the SecondFi wallet generated transaction signatures. In certain scenarios, attackers would be able to extract sensitive information encrypted via cryptographic secrets using transaction data on the blockchain. This allowed for the calculation of any keys impacted through the use of information that could already be found on the blockchain. The team also discovered the presence of the same vulnerable code in an unauthorized GitHub repository.

SecondFi stated that the flaw had been patched in the developer version of the software and the newly developed wallets no longer contain the flaw. However, despite this, the company decided to discontinue SecondFi as well as the Yoroi wallet due to the severity of the issue.

Recovery and Migration Become Immediate Urgencies

At SecondFi, efforts have been geared towards assisting affected users in recovering their lost funds and migrating safely. Testing of the recovery platform, which incorporates the use of zero-knowledge proof for the safety of users’ privacy and recovery, is ongoing. The company is planning on releasing the tested version of the platform in August 2026. In addition, SecondFi is working on wallet exporting, which will allow users to move funds to their desired wallets. This platform will be available from the beginning of August 2026.

Highlighted Crypto News:
Twenty One Capital CEO Jack Mallers Resigns After Bitcoin Strategy Dispute

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments