The Cardano SecondFi wallet is coming to an end after attackers exploited a flaw in its transaction signing software to steal 16.1 million ADA, worth approximately $2.4 million, from 374 wallets.
The service, which replaced EMURGO’s Yoroi wallet, said it will not resume normal operations despite patching the vulnerability and at the time securing 129 million ADA before attackers could access the funds.
The flaw allowed attackers to obtain private key material from transaction data visible on the Cardano blockchain, SecondFi said. The Cardano network itself was not compromised and hardware wallet users were not affected.
Groom Lake, the blockchain intelligence firm hired by EMURGO, found that the main attacker was sophisticated and well-funded. Some indicators point to North Korea’s Lazarus Group, although no attribution has been confirmed, the firm said.
A separate attacker targeted another set of wallets during the same period.
SecondFi expects to launch wallet export tools in early August and a zero-knowledge recovery portal later that month. EMURGO has funded an asset recovery wallet, but no firm distribution date has been given.




