SecondFi to wind down after $2.6M ADA theft linked to wallet flaw

Summary

SecondFi is shutting down its SecondFi and Yoroi wallet services after a security breach exposed a cryptographic flaw that led to the theft of about 16.1 million ADA, worth roughly $2.6 million. The incident affected 374 wallets. An independent investigation by Groom Lake concluded the attack came from a sophisticated external actor and found indicators possibly tied to North Korea’s Lazarus Group, though attribution is unconfirmed. The company says it is building a zero-knowledge-proof recovery tool and wallet export function to help users recover or migrate assets, with release now targeted for August after testing and third-party audit. Users have expressed frustration over repeated delays, since earlier guidance suggested recovery would begin within two weeks. SecondFi has not announced a reimbursement plan or confirmed whether it will compensate users from its own funds.