Cardano-based wallet service SecondFi is shutting down permanently after attackers exploited a flaw in its transaction signing software to drain roughly 16.1 million ADA — worth between $2.4 million and $2.6 million — from hundreds of user wallets, the company confirmed in an update published Wednesday [1][2].
The breach, first disclosed in late June, has left 374 affected users in limbo, waiting for recovery tools that have already slipped past one promised deadline and are now targeted for August [1].
What Went Wrong
The vulnerability was not in the Cardano blockchain itself but in SecondFi's own wallet software. Specifically, a flaw in the transaction signing layer allowed attackers to derive private key material directly from transaction data that is publicly visible on the Cardano blockchain [2]. That meant any wallet that had broadcast a transaction could, in principle, have its private keys reconstructed by a sufficiently capable attacker.
Hardware wallet users were not affected, and the Cardano network remained secure throughout the incident [2]. SecondFi, which had taken over operations of EMURGO's legacy Yoroi wallet, said it managed to secure 129 million ADA before attackers could reach those additional funds [2].
A separate attacker targeted a distinct set of wallets during the same window, suggesting the exploit may have attracted more than one threat actor once the vulnerability became known or detectable on-chain [2].
Lazarus Group Indicators, No Confirmed Attribution
SecondFi hired blockchain intelligence firm Groom Lake to conduct an independent investigation. The firm described the primary attacker as "sophisticated and well-funded" and found indicators potentially linked to North Korea's Lazarus Group — the state-sponsored hacking collective responsible for billions of dollars in crypto theft over the past decade [1][2]. However, both SecondFi and Groom Lake have stopped short of formal attribution, and no confirmation has been made public [1].
No Reimbursement Plan Announced
Despite the scale of the loss, SecondFi has not announced a direct reimbursement plan or indicated whether it will compensate affected users from its own reserves [1]. EMURGO, the blockchain infrastructure company behind the original Yoroi wallet, has funded an asset recovery wallet, but no firm distribution date has been set [2].
Cointelegraph reported that it contacted SecondFi for details on potential reimbursement and received no response by publication time; EMURGO also did not respond to earlier requests for comment [1].
Recovery Tools Delayed, Users Frustrated
The timeline for recovery has stretched considerably since the exploit was first disclosed. On June 27, SecondFi told users it had identified a recovery path and expected to begin the process within roughly two weeks [1]. Nearly a month later, the company said the tool is still in development.
The platform is now planning two distinct releases for August: wallet export functionality that will allow users to migrate their assets to another service, and a zero-knowledge proof-based recovery portal designed to help exploited users reclaim funds while minimizing the sensitive information they must disclose [1][2]. The recovery tool is still undergoing testing and is expected to receive a third-party security audit before launch [1].
In the meantime, SecondFi had previously advised affected users not to restore their recovery phrases into new Cardano wallets, warning that moving funds elsewhere "does not mitigate the risk" while the investigation was ongoing [1]. That guidance has left many users unable to act independently while waiting for the company's tools.
The frustration is palpable in public responses to SecondFi's Wednesday update. "But many of us were told our funds could be recovered within two weeks. Now we're being asked to wait even longer," one user wrote [1].
What Happens to SecondFi and Yoroi
SecondFi confirmed it will wind down both the SecondFi platform and Yoroi wallet services and will not resume normal operations, even after patching the underlying vulnerability [1][2]. The shutdown marks the end of the Yoroi wallet brand, which EMURGO had handed off to SecondFi as part of a broader transition.
The incident adds to a growing list of wallet-level exploits in the crypto industry — distinct from smart contract hacks — where flaws in key management or signing logic expose users even when the underlying blockchain remains intact. The fact that private keys could be reverse-engineered from publicly available on-chain data is a particularly stark reminder of how much security depends on implementation details that users rarely see or audit.
What to Watch
The most immediate question is whether SecondFi's August timeline for recovery tools holds. A second delay would further erode user trust and could prompt regulatory scrutiny, particularly given the potential Lazarus Group connection. Separately, Groom Lake's investigation remains open, and any confirmed attribution to North Korea would elevate the incident from a software failure to a geopolitically significant crypto theft. Users should also watch for whether EMURGO makes any public statement about compensation, given its historical role in the Yoroi ecosystem.
