HomeAll NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

SecondFi to wind down after $2.6M ADA theft linked to wallet flaw

Created at 22 Jul · 9:56 AM1 source↑ Market-relevant
IN SHORT

Cardano-based wallet SecondFi will shut down after a security breach resulted in the theft of approximately $2.6 million worth of ADA. Affected users are still awaiting recovery tools, now expected in August.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

16.1 million ADAstolen ADA amount
$2.6 millionvalue of stolen ADA
374affected wallets

Who's Involved

SecondFi
Cardano-based wallet preparing to shut down after security breach
Groom Lake
Blockchain intelligence provider that identified the attacker
Lazarus Group
Potential suspect group linked to the attack

↳ Why This Matters

The shutdown of SecondFi highlights ongoing security vulnerabilities in cryptocurrency wallets and the potential for significant financial losses for users. The delay in recovery tools and the potential link to a state-sponsored hacking group underscore the risks associated with digital asset management.

Key facts

  • SecondFi will cease operations following a $2.6 million ADA theft.
  • The theft of 16.1 million ADA was due to a cryptographic flaw in the wallet software.
  • An investigation indicated a sophisticated actor, possibly North Korea's Lazarus Group, was involved.
  • 374 wallets were affected by the security breach.
  • Recovery tools and migration options are planned for release in August.
  • Users are frustrated by the extended timeline for asset recovery.

Cardano-based wallet service SecondFi is set to wind down operations after a significant security breach led to the theft of approximately $2.6 million worth of ADA. The platform disclosed that attackers stole 16.1 million ADA due to a cryptographic flaw in its wallet software, affecting 374 user wallets.

An independent investigation by blockchain intelligence provider Groom Lake identified a sophisticated external actor, with indicators potentially pointing towards North Korea's Lazarus Group, though no definitive attribution has been made. This revelation comes nearly a month after SecondFi first reported the exploit in late June.

SecondFi is developing a recovery tool utilizing zero-knowledge proofs, which is currently undergoing testing and is slated for a third-party audit before a planned release in August. Additionally, the platform is preparing wallet export functionality to enable users to transfer their assets to alternative services. However, no direct reimbursement plan has been announced.

The extended timeline for recovery has caused frustration among affected users, many of whom were initially led to believe their funds could be recovered within two weeks. The company had previously advised users against restoring recovery phrases into new wallets while the investigation was ongoing.

Frequently asked questions

The theft was caused by a cryptographic flaw in SecondFi's wallet software.

Approximately 16.1 million ADA, valued at about $2.6 million, was stolen.

An investigation suggested a sophisticated external actor, potentially linked to North Korea's Lazarus Group, though attribution is not confirmed.

SecondFi plans to release recovery tools and migration options in August, after initial expectations of a two-week recovery period.

What Happens Next

01SecondFi plans to release recovery tools in August.
02Wallet export functionality will be made available for asset migration.
03A third-party auditor will review the recovery tool before its release.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

SecondFi disclosed a security breach resulting in the theft of 16.1 million ADA.
The stolen ADA was valued at approximately $2.6 million.
An investigation suggested a sophisticated external actor, potentially linked to North Korea's Lazarus Group, was behind the attack.
The breach affected 374 wallets.
SecondFi announced plans to develop a recovery tool using zero-knowledge proofs.
Wallet export functionality is also being prepared to allow users to migrate assets.
Users expressed frustration over the delayed recovery timeline, which was initially expected within two weeks.
SecondFi is now targeting August for the release of recovery tools and migration options.

Sources

T1
SecondFi to wind down after $2.6M ADA theft linked to wallet flawSecondFi will wind down after a $2.6 million ADA theft, while users still await recovery tools that were initially expected within weeks of the exploit.Cointelegraph

Related Stories

Midnight token rebounds 19% after Wanchain bridge hack, Hoskinson calls for ZK revamp
22 Jul · 11:56 AM
Balance Coin Crashes 99% After $915K Exploit
22 Jul · 3:31 AM
Zilliqa Ledger app vulnerability allows private key recovery
22 Jul · 12:06 PM
Movement Labs Files for Chapter 11 Bankruptcy Amidst Token Scandal
21 Jul · 6:06 PM
Jack Mallers Steps Down as CEO of Bitcoin Treasury Twenty One Capital
21 Jul · 12:10 PM