Finst

SecondFi Shuts Down After 16.1 Million ADA Theft

The issue was in the signing software, not Cardano itself. SecondFi is building recovery tools after 374 wallets and 16.1 million ADA were affected.

SecondFi Shuts Down After 16.1 Million ADA Theft

Key Takeaways

  • SecondFi is shutting down after an attack that used a flaw in signing software to steal 16.1 million ADA, worth about $2.4 million.
  • A total of 374 wallets were affected; hardware wallets were not hit and the vulnerability has already been patched.
  • SecondFi will not resume normal operations and plans to launch export tools in early August, followed later by a zero-knowledge recovery portal.

Cardano wallet SecondFi is shutting down its services after attackers exploited a flaw in transaction signing software to steal 16.1 million ADA, worth about $2.4 million (€2.1 million). In total, 374 wallets were affected. The crypto company says the issue has already been fixed, but it will not return to normal operations.

How the Attack Worked

According to SecondFi, the attackers were able to piece together private key material from transaction data that was visible on the Cardano blockchain. The problem was not with the Cardano network itself, and users who relied on a hardware wallet were not affected. The company also said it had protected another 129 million ADA at the time of the attack, keeping it out of reach before the attackers could access it.

The technical flaw appears to have involved predictable randomization in the seed and key derivation process, which let private keys be rebuilt from public blockchain data after transactions were signed. That makes this kind of incident especially serious, since the attack does not necessarily require breaking the network itself. Instead, it can come down to how wallet software generates keys and signs transactions.

Investigation Points to a Sophisticated Attacker

Blockchain intelligence firm Groom Lake, which was hired by EMURGO, describes the main attacker as sophisticated and well-funded. There are also signs that point to North Korea’s Lazarus Group, but there is no confirmed attribution. SecondFi said a separate attacker was also active during the same period and went after a different group of wallets.

For European crypto users, the takeaway is that wallet security is about more than just protecting a seed phrase. The software layer matters too. On Cardano and other networks where transactions are visible on-chain, a weakness in signing or key derivation can directly affect the security of user funds. That also fits with broader concerns around private keys, which security researchers say are behind a large share of crypto hack losses.

Recovery and Wind-Down

SecondFi says it plans to roll out wallet export tools in early August, followed by a zero-knowledge recovery portal later in the month. EMURGO has funded an asset recovery wallet, but there is still no set date for payouts or distribution. For now, that leaves the recovery process open while the service itself moves into a wind-down phase.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.