SecondFi, the Cardano wallet that replaced EMURGO’s Yoroi Wallet, is permanently shutting down after a software vulnerability allowed attackers to steal 16.1 million ADA, worth approximately $2.4 million, from 374 user wallets. Despite successfully patching the flaw and securing millions more in customer funds before they could be stolen, the company said the severity of the breach left it with no viable path to continue operations.
The incident has become one of the most significant wallet security failures in Cardano’s history because the vulnerability did not target the blockchain itself. Instead, attackers exploited a flaw in SecondFi’s transaction-signing software that exposed users’ private keys through publicly visible blockchain transaction data. The attack underscores how weaknesses in wallet software can compromise user funds even when the underlying blockchain remains secure.
According to SecondFi, the exploit originated from a subtle bug in how the wallet generated cryptographic signatures for transactions.
The flaw allowed attackers to derive sensitive private key material from transaction information that was already visible on the Cardano blockchain. Once attackers reconstructed the affected private keys, they were able to drain funds directly from user wallets without compromising the Cardano network itself. Hardware wallet users were not affected because the vulnerability existed only within SecondFi’s software implementation.
Between the attack and emergency response efforts, approximately 16.1 million ADA—valued at roughly $2.4 million at the time—was stolen from 374 compromised wallets.
SecondFi also revealed that it successfully secured approximately 129 million ADA before attackers could reach those funds. Those assets have been placed into a recovery wallet while the company works toward reimbursing affected users through a structured recovery process.
Although engineers patched the vulnerability, SecondFi announced it will permanently discontinue both the SecondFi and Yoroi wallet platforms.
Instead of rebuilding the wallet, the company will focus entirely on helping affected users recover their remaining assets.
Recovery plans include:
The company has not provided a firm timeline for distributing recovered assets.
Blockchain intelligence firm Groom Lake, hired by EMURGO to investigate the incident, concluded that the primary attacker appeared highly sophisticated and well-funded.
Investigators said certain indicators overlap with tactics previously associated with North Korea’s Lazarus Group, although they stopped short of formally attributing the attack to the state-sponsored hacking organization. A second, unrelated attacker also exploited vulnerable wallets during the incident.
SecondFi emphasized that the exploit did not originate from the Cardano blockchain itself.
Instead, the weakness existed solely within the wallet’s transaction-signing implementation. This distinction is important because the blockchain’s consensus mechanism, cryptography, and network security remained fully intact throughout the incident.
The breach highlights a recurring challenge across the crypto industry: even when blockchain networks remain secure, vulnerabilities in wallet software, smart contracts, or third-party applications can still expose user funds.
President Donald Trump is expected to meet with executives from some of the biggest names in crypto and…
Grayscale Investments has quietly abandoned plans to launch three cryptocy exchange-traded funds tied to Cardano (ADA), Polkadot…
Ether.fi is making a major push beyond Ethereum staking by transforming its self-custodial DeFi app into…
The Blockchain Association is throwing its support behind Custodia Bank in a potentially consequential Supreme Court battle over whether…
Nearly 14,000 Trezor customers have had personal information exposed after an unauthorized party breached systems belonging to ShipMonk,…
Bitcoin has entered one of its quietest trading periods in years, with 30-day realized volatility hovering near…