Cardano Wallet SecondFi Announces Closure Following $2.6M ADA Security Breach

Cardano Wallet SecondFi Announces Closure Following $2.6M ADA Security Breach

Following a $2.6 million ADA security breach, SecondFi announces its closure as affected users continue waiting for promised recovery solutions that were originally scheduled for delivery weeks ago.

The Cardano-based digital wallet platform SecondFi is moving toward a complete shutdown following a major security incident that revealed significant vulnerabilities in wallet security protocols and has left hundreds of customers waiting for promised asset recovery solutions.

In a statement released on Wednesday, SecondFi announced plans to discontinue both SecondFi and Yoroi wallet operations after malicious actors successfully stole approximately 16.1 million ADA tokens, valued at around $2.6 million, by exploiting a cryptographic vulnerability within the wallet's software architecture.

According to the platform's announcement, blockchain intelligence firm Groom Lake conducted an independent forensic investigation that traced the attack to a highly skilled external threat actor and uncovered potential connections to the Lazarus Group operating out of North Korea, though definitive attribution remains unconfirmed. The company also disclosed that the security breach impacted a total of 374 individual wallets.

The Wednesday announcement arrived approximately one month following SecondFi's initial disclosure of the security exploit in late June, leaving affected customers still anticipating the recovery tools and migration capabilities that the organization now states are targeted for deployment sometime in August.

SecondFi plans recovery tools as users await next steps

According to SecondFi's announcement, the company is currently building a specialized recovery tool utilizing zero-knowledge proof technology designed to enable affected customers to retrieve their digital assets while minimizing the amount of sensitive information they must disclose during the recovery process.

The recovery solution remains in active testing phases and will undergo comprehensive evaluation by an independent third-party security auditor prior to its anticipated August release date.

Additionally, the platform is working on wallet export features that will enable customers to transfer their digital assets to alternative wallet services. Notably, SecondFi has not revealed any direct reimbursement strategy or indicated whether affected users will receive compensation directly from the company's own financial reserves.

Users question recovery timeline as SecondFi winds down

The most recent communication from SecondFi has generated considerable frustration among certain users who indicate they remain without a definitive solution for recovering or transferring their digital holdings following the security exploit.

Previous instructions issued by the platform cautioned affected customers against restoring their recovery phrases into alternative Cardano wallet applications, warning that transferring assets to different platforms "does not mitigate the risk" during the ongoing investigation into the security incident.

In a June 27 communication, SecondFi indicated it had successfully identified a viable recovery pathway and anticipated initiating the recovery process within approximately two weeks following the completion of necessary testing protocols and security assessments. Nearly one month following that announcement, the company now reports that the recovery tool remains under active development with an updated expected launch timeframe of August.

But many of us were told our funds could be recovered within two weeks. Now we're being asked to wait even longer

Cointelegraph reached out to SecondFi requesting additional information regarding potential reimbursement strategies but had not received a response at the time of publication. EMURGO similarly did not provide responses to previous inquiries seeking comment on the situation.