
Cardano wallet SecondFi has announced its permanent shutdown following a major security breach that resulted in the theft of 16.1 million ADA worth approximately $2.4 million from 374 wallets. According to reports from CoinDesk, the service, which replaced EMURGO's Yoroi wallet, will not resume normal operations despite patching the vulnerability that enabled the attack. The breach stemmed from a flaw in transaction signing software that allowed attackers to derive private key material from transaction data visible on the Cardano blockchain.
The Cardano network itself was not compromised, and hardware wallet users were not affected by the attack. As reported by CoinDesk, investigation by Groom Lake, the blockchain intelligence firm hired by EMURGO, revealed that the primary attacker exhibited sophisticated techniques and substantial funding, with some indicators pointing to North Korea's Lazarus Group, though no formal confirmation has been made. A separate attacker targeted another set of wallets during the same period, demonstrating the coordinated nature of the breach.
According to CoinDesk, SecondFi expects to release wallet export tools in early August and a zero-knowledge recovery portal later that month. The company has funded an asset recovery wallet, though no firm distribution date has been given for the recovered funds. At the time of the attack, SecondFi had secured 129 million ADA before attackers could reach the funds, providing some protection against the theft.
Despite the significant security breach, ADA has shown remarkable resilience in the market. As reported by AMBCrypto, the token was trading near $0.17 at the time of writing, with no notable sell-off following news of the SecondFi wallet theft. The derivatives market also remained stable, with Aggregated Open Interest rising above $210 million before settling near $206.3 million, while the Average Funding Rate indicated that long traders were willing to pay to maintain their positions. This market response suggests that traders view the SecondFi incident as an isolated wallet issue rather than a systemic Cardano security concern.
While there is no evidence that the vulnerability extends beyond SecondFi, the incident highlights the importance of continued security reviews across the wider Cardano wallet ecosystem. As noted by AMBCrypto, the involvement of a second attacker and the possible Lazarus Group link add complexity to the situation, though no formal confirmation has been made regarding these connections. The breach serves as a reminder of the ongoing security challenges in the cryptocurrency wallet sector and the need for enhanced protection measures across all Cardano-based wallet services.