SecondFi says wallet attack may be linked to Lazarus indicators, targets August 2026 launch for recovery tool

SecondFi says wallet attack may be linked to Lazarus indicators, targets August 2026 launch for recovery tool

N
News Editor
2026-07-22 08:22:20
SecondFi, a Cardano wallet service provider, has released an update on its security incident investigation, saying forensic work commissioned by EMURGO and carried out by independent blockchain forensics firm Groom Lake identified two separate attackers. According to the update, the primary attacker used advanced techniques and showed some overlap with known indicators tied to North Korea’s Lazarus Group, though the assessment is still ongoing. A second attacker appeared to operate independently and used different wallet addresses. SecondFi said the root cause was a cryptographic flaw in its wallet software during per-transaction signature generation. In theory, that flaw could allow an attacker to derive private key material for affected wallets from publicly available on-chain data. The company added that the vulnerable code had previously been published without authorization to a public GitHub repository, and said it is continuing to assess the situation while cooperating with authorities. SecondFi said the flaw has now been fixed and that wallets created with the patched version are not affected. The company also said it will shut down both SecondFi and Yoroi wallets, roll out a wallet export function before then, and release a zero-knowledge-proof-based asset recovery tool in August 2026.
SecondFiYoroiLazarus GroupCardanoADAsecurity incidentzero-knowledge proofpolicy regulation

Cardano wallet service provider SecondFi has published an update on its security incident, following an investigation commissioned by EMURGO and conducted by independent blockchain forensics firm Groom Lake.

The findings point to two separate attackers. SecondFi said the primary attacker used advanced methods, and some indicators overlap with known activity associated with North Korea’s Lazarus Group. That assessment is still being reviewed. The company added that signs tied to a second attacker were independent from the primary intrusion and involved different wallet addresses.

Cryptographic flaw identified as root cause

SecondFi said the underlying cause of the incident was a cryptographic flaw in the wallet software during the generation of per-transaction signatures. According to the company, the flaw could theoretically allow attackers to derive private key material for affected wallets from public on-chain data.

The company also said the affected code had previously been published without authorization to a public GitHub repository. SecondFi said it is continuing to assess the matter and is cooperating with the relevant authorities in their investigation.

The vulnerability has now been fixed, SecondFi said, and newly created wallets using the patched version are not affected.

SecondFi and Yoroi wallets to be shut down

SecondFi said it will close both the SecondFi and Yoroi wallets.

On asset recovery, the company said it is developing a zero-knowledge-proof-based recovery tool and expects to release it in August 2026. Before that launch, it plans to add a wallet export feature so users can move assets to other wallets.

Previously disclosed losses and fund movements

Foresight News had earlier reported that SlowMist estimated losses from the SecondFi security incident at more than $20 million.

SecondFi later said there were four fund outflow events in total, three of which were carried out by external attackers. Those transfers moved about 16 million ADA out of 374 addresses. The company also said it had transferred about 129 million ADA to an independent third-party custodian for safekeeping.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.