SecondFi, the Cardano wallet that replaced EMURGO’s Yoroi Wallet, is permanently shutting down after a software vulnerability allowed attackers to steal 16.1 million ADA, worth approximately $2.4 million, from 374 user wallets. Despite successfully patching the flaw and securing millions more in customer funds before they could be stolen, the company said the severity of the breach left it with no viable path to continue operations.
The incident has become one of the most significant wallet security failures in Cardano’s history because the vulnerability did not target the blockchain itself. Instead, attackers exploited a flaw in SecondFi’s transaction-signing software that exposed users’ private keys through publicly visible blockchain transaction data. The attack underscores how weaknesses in wallet software can compromise user funds even when the underlying blockchain remains secure.
According to SecondFi, the exploit originated from a subtle bug in how the wallet generated cryptographic signatures for transactions.
The flaw allowed attackers to derive sensitive private key material from transaction information that was already visible on the Cardano blockchain. Once attackers reconstructed the affected private keys, they were able to drain funds directly from user wallets without compromising the Cardano network itself. Hardware wallet users were not affected because the vulnerability existed only within SecondFi’s software implementation.
Between the attack and emergency response efforts, approximately 16.1 million ADA—valued at roughly $2.4 million at the time—was stolen from 374 compromised wallets.
SecondFi also revealed that it successfully secured approximately 129 million ADA before attackers could reach those funds. Those assets have been placed into a recovery wallet while the company works toward reimbursing affected users through a structured recovery process.
Although engineers patched the vulnerability, SecondFi announced it will permanently discontinue both the SecondFi and Yoroi wallet platforms.
Instead of rebuilding the wallet, the company will focus entirely on helping affected users recover their remaining assets.
Recovery plans include:
The company has not provided a firm timeline for distributing recovered assets.
Blockchain intelligence firm Groom Lake, hired by EMURGO to investigate the incident, concluded that the primary attacker appeared highly sophisticated and well-funded.
Investigators said certain indicators overlap with tactics previously associated with North Korea’s Lazarus Group, although they stopped short of formally attributing the attack to the state-sponsored hacking organization. A second, unrelated attacker also exploited vulnerable wallets during the incident.
SecondFi emphasized that the exploit did not originate from the Cardano blockchain itself.
Instead, the weakness existed solely within the wallet’s transaction-signing implementation. This distinction is important because the blockchain’s consensus mechanism, cryptography, and network security remained fully intact throughout the incident.
The breach highlights a recurring challenge across the crypto industry: even when blockchain networks remain secure, vulnerabilities in wallet software, smart contracts, or third-party applications can still expose user funds.
Elon Musk's artificial intelligence company xAI has filed a federal lawsuit challenging Minnesota's landmark law banning AI-powered "nudification" technology, arguing…
Bitcoin climbed toward $65,000 as an unusual shift in traditional financial markets created one of the rarest conditions…
Hyperscale Data has sold 100 Bitcoin to accelerate development of its planned artificial intelligence campus in Michigan, sending shares…
A newly launched memecoin called PIPEDOG ($PIPEDOG) became the latest breakout token on Robinhood Chain, surging more than 140x within…
BNY, the world's largest custodian bank, is bringing one of its core financial businesses onto…
A bipartisan group of U.S. senators has reportedly reached a new compromise on the ethics provisions of…