SecondFi said July 22 that it will wind down its wallet service after a cryptographic flaw enabled attackers to steal approximately 16.1 million ADA, valued by the company at about $2.6 million, from 374 wallets between June 21 and June 23.
Key Takeaways
- SecondFi’s investigation attributes the loss of approximately 16.1 million ADA from 374 wallets to a cryptographic signing flaw.
- The wallet operator patched the flaw but said SecondFi and the former Yoroi service will still be wound down.
- A wallet export function is expected in early August, while a zero-knowledge recovery portal is targeted for later in August.
- Investigators identified two apparently separate attackers, with only potential indicators of overlap with DPRK-linked Lazarus Group activity.
What Happened?
The July 22 update is the clearest account yet of the incident that disrupted SecondFi, the self-custody wallet service that replaced EMURGO’s Yoroi wallet. SecondFi said unauthorized transfers occurred during a June 21-23 window and affected 374 wallets.
EMURGO hired blockchain intelligence firm Groom Lake to review code, code history and public blockchain data. According to SecondFi, the review found a primary operation that appeared sophisticated, external and well funded, plus activity by a second party affecting a different set of wallets.
The company described possible overlap with known North Korea-linked Lazarus Group activity as an indicator still being assessed, not a confirmed attribution. That distinction matters because the public evidence cited in the update does not identify a named attacker with certainty.
An update regarding the recent security incident involving SecondFi
— SecondFi (@secondfiapp) July 22, 2026
What happened to SecondFi
Between June 21st and 23rd, SecondFi experienced a security incident that resulted in approximately 16.1 million ADA (~$2.6 million) being stolen from 374 wallets. We want to provide…
How the Signing Flaw Worked?
SecondFi said the weakness was in the software used to generate per transaction signatures. A value that should have depended on secret information could, under certain conditions, be calculated from public transaction data.
That failure could expose enough private-key material for an attacker to derive control over affected wallet keys from information already visible on the Cardano blockchain. The incident therefore centered on the wallet’s signing implementation rather than a compromise of Cardano’s underlying network.
The operator also said a copy of the relevant code had been published without authorization in a public GitHub repository. It is still assessing how that publication occurred and said it is cooperating with authorities. The update does not establish whether the copied code directly caused the theft or merely exposed the same flaw.
Recovery and Migration Timeline
SecondFi said the flaw has been patched and that newly created wallets using corrected software are not known to be affected. Even so, the company will not restart normal operations and will limit its work to asset recovery and user migration.
A wallet export function is expected by early August 2026 so users can move assets to another wallet. A separate recovery portal using zero-knowledge proofs is in testing and is expected later in August after review by a specialist third-party auditor.
The zero-knowledge design is intended to let affected users initiate claims while limiting the information they must disclose. SecondFi has not announced a date for distributing recovered assets, and its July 22 update leaves eligibility, implementation and recovery outcomes unresolved.
The company has also warned users about fake recovery emails, cloned applications and impersonation attempts. Its official update says SecondFi will not request private keys, recovery phrases or wallet credentials and will not contact users first through direct messages.
CoinLaw’s Takeaway
The shutdown shows how a narrow implementation failure in self-custody software can become a direct asset-loss event even when the underlying blockchain continues to operate as designed. For affected users, the practical issue is now the integrity and timing of SecondFi’s export and claims systems rather than restoration of the original wallet service.
The August timeline creates two separate execution risks: safely moving unaffected assets and verifying claims for stolen funds. Independent auditing of the recovery portal may reduce technical risk, but the final recovery rate, distribution schedule and attacker attribution remain unknown.