SecondFi, a Cardano wallet provider that succeeded EMURGO’s Yoroi wallet, is shutting down after a critical software vulnerability enabled attackers to steal 16.1 million ADA, valued at $2.4 million, from 374 user wallets. The company confirmed that the breach allowed bad actors to derive sensitive private keys directly from blockchain transaction data, enabling unauthorized access to users’ funds.
Details of the exploit
SecondFi stated that the vulnerability was found in the transaction signing software, which failed to securely protect key material. This flaw made it possible to reconstruct users’ private keys using information displayed in Cardano blockchain transactions. Notably, the Cardano blockchain itself remained uncompromised and unaffected by the incident, and users of hardware wallets did not face any risk due to the isolation provided by secure devices.
The platform managed to secure 129 million ADA before attackers could reach those funds, helping to reduce the impact of the breach. Normal wallet operations have been discontinued, as SecondFi confirmed that it does not intend to resume business despite fixing the software error.
Groom Lake, a blockchain intelligence firm retained by EMURGO, investigated the incident and concluded that the primary attacker showed a high degree of sophistication and access to substantial resources. While some indicators suggested links to North Korea’s Lazarus Group, Groom Lake stated there is no definitive confirmation of attribution at this time.
A secondary attacker also exploited the vulnerability, targeting a separate set of wallets during the same breach period. SecondFi provided assurances that hardware-stored wallets had no exposure to these attacks.
Mini dictionary: Groom Lake, a blockchain security and intelligence firm specializing in forensic investigations and threat attribution for on-chain exploits. The firm was chosen by EMURGO to analyze the SecondFi security breach.
SecondFi described the breach as originating from a weakness in its transaction signing software, which let attackers reconstruct private key material and compromise user accounts, but emphasized that hardware wallet users were not affected.
User support and next steps
SecondFi plans to release wallet export tools in early August, enabling users to safely retrieve and transfer their Cardano holdings. In addition, a zero-knowledge recovery portal is scheduled for launch later in the same month to facilitate a privacy-preserving recovery process for affected users.
EMURGO, the blockchain technology company that initially developed the Yoroi wallet and later transitioned to SecondFi, has funded an asset recovery wallet. However, SecondFi has not announced any specific timelines for the return of lost ADA, and the distribution date for recovered assets remains undetermined.
The Cardano blockchain was not compromised by these exploits, and users employing hardware wallets face no risk from this vulnerability, SecondFi reported.
A separate attacker who used the same exploit also targeted wallets during the breach period. SecondFi stated that coordination with blockchain security partners and the broader Cardano community is ongoing as they work toward mitigating further fallout from the incident.
| Wallet type | Affected by breach |
|---|---|
| Software wallet (SecondFi) | Yes |
| Hardware wallet | No |
SecondFi’s decision to shut down comes as the company continues to collaborate with stakeholders to deliver support tools for users and investigate the source of the incident.




