SecondFi released an update on its security incident investigation on July 23, disclosing that between June 21 and 23, 374 wallets lost about 16.1 million ADA (about $2.6 million) to theft. EMURGO has hired the independent forensics investigation firm Groom Lake to conduct the probe, concluding that the primary attacker is currently assessing whether there is potential overlap with the Lazarus Group.
Groom Lake Investigation: Two batches of independent attackers potentially linked to the Lazarus Group
According to the independent forensics investigation commissioned by EMURGO through Groom Lake, this incident involves two groups of independent attackers:
Primary attacker: Groom Lake said that behind the authorized transfers, the main actor “is precise, external, and well-funded,” showing “indications consistent with the activities of professional, state-related threat actors.” Certain indications are being evaluated for potential overlap with the Lazarus Group (a DPRK-related threat organization), but no final conclusion has yet been reached.
Second-party attacker: Based on current evidence, it appears unrelated to the primary actions. Independent attacks were carried out against different wallet clusters within the same time period, and so far no overlap has been found among the affected wallets.
Cryptographic vulnerability root cause and the unauthorized GitHub code copy
According to SecondFi’s official update, the root cause of the incident lies in “highly subtle defects in how the wallet software generates the signature for each transaction”: a value that should be derived from secret information can, under certain conditions, be computed from publicly available transaction data. This may allow the affected private key material to be derived from information visible on the public blockchain.
The same cryptographic flaw also appears in a related code copy that was not authorized for release to a public GitHub repository. SecondFi said it is currently continuing to assess the circumstances surrounding the code release and is cooperating with relevant authorities.
Recovery tool, wallet export feature, and user safety migration
According to SecondFi’s official statement, the subsequent arrangements are as follows:
Vulnerability fix status: Fixed; new wallets created with the patched software are not affected by this issue
SecondFi and Yoroi wallets: Given the severity of the incident, a phased shutdown has been decided
Zero-knowledge proof recovery tool: Currently in the testing stage, expected to be released in Aug. 2026; third-party auditors are reviewing it (not completed yet)
Wallet export feature: Allows users to migrate assets to other wallets of their choice, expected to be released in early Aug. 2026
Security reminder: SecondFi emphasized that it will not proactively DM users and will not ask users to provide private keys or seed phrases
FAQ
How much ADA was stolen and how many wallets were affected in SecondFi’s security incident?
According to SecondFi’s official update on July 23, 2026, between June 21 and 23, 2026, about 16.1 million ADA (about $2.6 million) was stolen from 374 wallets.
What is Groom Lake’s conclusion on the attackers’ identities?
According to Groom Lake’s investigation, the indications for the primary attacker “are consistent with the activities of professional, state-related threat actors.” Some indications are being evaluated for potential overlap with the Lazarus Group (a DPRK-related organization), but no final determination has been made yet; in addition, another second-party independent attacker conducted attacks against different wallet clusters, with no overlap with the primary attacker.
When will SecondFi’s asset recovery tool and wallet export feature be released?
According to SecondFi’s official statement, the zero-knowledge proof-based recovery tool is currently in the testing stage and is expected to be released in Aug. 2026; the wallet export feature is expected to be released in early Aug. 2026; the specific timing will be subject to announcements via SecondFi’s official channels.