Key Takeaways:
- SecondFi is shutting down after a $2.6 million ADA wallet exploit
- Attackers stole 16.1 million ADA from 374 wallets via a cryptographic flaw
- Recovery tools are now expected in August, nearly a month after the initial disclosure
Key Takeaways:

Cardano-based wallet provider SecondFi said it will wind down its platform and the Yoroi wallet service after attackers stole 16.1 million ADA, worth about $2.6 million, from 374 wallets through a cryptographic flaw in its software.
An independent investigation by blockchain intelligence firm Groom Lake identified a sophisticated external actor behind the attack and found indicators potentially linked to North Korea's Lazarus Group, though no attribution has been confirmed, SecondFi said in a July 22 update.
The breach stemmed from a flaw in SecondFi's wallet encryption technology, the company said. The exploit was first disclosed in late June, and affected users have been waiting for recovery tools that were initially expected within two weeks of the incident.
SecondFi is developing a recovery tool based on zero-knowledge proofs to help affected users reclaim assets while limiting the information they need to share. The tool is undergoing testing and will be reviewed by a third-party auditor before a planned release in August. The platform is also preparing a wallet export feature to allow users to migrate assets to another service. SecondFi has not announced a direct reimbursement plan or said whether it will compensate users from its own funds.
The company's timeline has drawn frustration from users. On June 27, SecondFi said it had identified a recovery path and expected to begin the process within about two weeks after completing testing and security reviews. Nearly a month later, the recovery tool remains under development and is now expected in August. Earlier guidance advised affected users not to restore recovery phrases into new Cardano wallets, saying moving funds elsewhere "does not mitigate the risk" while the investigation was ongoing.
The shutdown of SecondFi and Yoroi raises questions about wallet security within the Cardano ecosystem and may push users toward more established wallet providers. The potential Lazarus Group link also adds to a growing list of North Korean-linked crypto exploits, which blockchain analytics firm Chainalysis has estimated at more than $3 billion in stolen funds since 2017.
This article is for informational purposes only and does not constitute investment advice.