SecondFi Security Incident Update: 374 Wallets Lost 16.10 Million ADA Tokens

ADA0.98%
Key Takeaways
  • SecondFi disclosed on July 23, 2026 that 374 wallets lost 16.1 million ADA during June 21-23 incident.
  • A cryptographic flaw in wallet software signature generation enabled private key derivation from public blockchain data.
  • SecondFi will release wallet export functionality in August 2026 and shut down SecondFi and Yoroi wallets.

SecondFi released an update on its security incident investigation on July 23, disclosing that between June 21 and 23, 374 wallets lost about 16.1 million ADA (about $2.6 million) to theft. EMURGO has hired the independent forensics investigation firm Groom Lake to conduct the probe, concluding that the primary attacker is currently assessing whether there is potential overlap with the Lazarus Group.

Groom Lake Investigation: Two batches of independent attackers potentially linked to the Lazarus Group

According to the independent forensics investigation commissioned by EMURGO through Groom Lake, this incident involves two groups of independent attackers:

Primary attacker: Groom Lake said that behind the authorized transfers, the main actor “is precise, external, and well-funded,” showing “indications consistent with the activities of professional, state-related threat actors.” Certain indications are being evaluated for potential overlap with the Lazarus Group (a DPRK-related threat organization), but no final conclusion has yet been reached.

Second-party attacker: Based on current evidence, it appears unrelated to the primary actions. Independent attacks were carried out against different wallet clusters within the same time period, and so far no overlap has been found among the affected wallets.

Cryptographic vulnerability root cause and the unauthorized GitHub code copy

According to SecondFi’s official update, the root cause of the incident lies in “highly subtle defects in how the wallet software generates the signature for each transaction”: a value that should be derived from secret information can, under certain conditions, be computed from publicly available transaction data. This may allow the affected private key material to be derived from information visible on the public blockchain.

The same cryptographic flaw also appears in a related code copy that was not authorized for release to a public GitHub repository. SecondFi said it is currently continuing to assess the circumstances surrounding the code release and is cooperating with relevant authorities.

Recovery tool, wallet export feature, and user safety migration

According to SecondFi’s official statement, the subsequent arrangements are as follows:

Vulnerability fix status: Fixed; new wallets created with the patched software are not affected by this issue

SecondFi and Yoroi wallets: Given the severity of the incident, a phased shutdown has been decided

Zero-knowledge proof recovery tool: Currently in the testing stage, expected to be released in Aug. 2026; third-party auditors are reviewing it (not completed yet)

Wallet export feature: Allows users to migrate assets to other wallets of their choice, expected to be released in early Aug. 2026

Security reminder: SecondFi emphasized that it will not proactively DM users and will not ask users to provide private keys or seed phrases

FAQ

How much ADA was stolen and how many wallets were affected in SecondFi’s security incident?

According to SecondFi’s official update on July 23, 2026, between June 21 and 23, 2026, about 16.1 million ADA (about $2.6 million) was stolen from 374 wallets.

What is Groom Lake’s conclusion on the attackers’ identities?

According to Groom Lake’s investigation, the indications for the primary attacker “are consistent with the activities of professional, state-related threat actors.” Some indications are being evaluated for potential overlap with the Lazarus Group (a DPRK-related organization), but no final determination has been made yet; in addition, another second-party independent attacker conducted attacks against different wallet clusters, with no overlap with the primary attacker.

When will SecondFi’s asset recovery tool and wallet export feature be released?

According to SecondFi’s official statement, the zero-knowledge proof-based recovery tool is currently in the testing stage and is expected to be released in Aug. 2026; the wallet export feature is expected to be released in early Aug. 2026; the specific timing will be subject to announcements via SecondFi’s official channels.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments