SecondFi Shuts Down After $2.4M Cardano Wallet Security Breach

ADA-5.58%
ZIL-0.16%
Key Takeaways
  • SecondFi permanently ceased operations on July 22 after a June security breach stole 16.1 million ADA.
  • The breach resulted from flawed nonce generation in SecondFi's Android app released June 8, exposing users' private keys.
  • EMURGO is developing a zero-knowledge recovery portal expected to release in August for affected users.

SecondFi, the Cardano wallet launched in April 2026 as EMURGO's successor to the Yoroi platform, announced on July 22 that it will permanently cease operations following a security breach that resulted in the theft of 16.1 million ADA from 374 user wallets. The stolen assets were valued at approximately $2.4 million at the time of the June incident. The breach originated from a cryptographic flaw in an Android application update released on June 8, which exposed users' private keys through transaction signatures visible on Cardano's public blockchain. EMURGO, one of Cardano's three founding organizations alongside the Cardano Foundation and Input Output Global, confirmed that SecondFi will not resume operations and stated its focus will shift exclusively to asset recovery for affected users, though no reimbursement timeline has been provided.

Android App Update Exposed Private Keys Through Flawed Nonce Generation

The vulnerability stemmed from SecondFi's implementation of Cardano's extended Ed25519 digital signature scheme. Standard protocol requires each transaction signature to rely on a unique nonce generated using both transaction data and secret key material stored on the user's device, ensuring signatures cannot reveal the underlying private key. SecondFi's Android application, however, generated the nonce using only public transaction information while excluding the required secret component. Cybersecurity researchers confirmed this implementation mistake allowed anyone monitoring Cardano's blockchain to calculate users' private keys directly from transaction signatures. Independent researchers demonstrated the vulnerability by reconstructing private keys solely from publicly available blockchain records. Security analysts indicated the implementation represented one of the most severe cryptographic failures seen in a production cryptocurrency wallet. Because the compromised information is embedded in permanent blockchain records, EMURGO warned users that restoring an affected recovery phrase into another Cardano wallet would not eliminate the risk, requiring users to completely abandon compromised wallet addresses and generate entirely new keys.

Attackers Drained 16.1 Million ADA Across Four Separate Events

The exploit occurred between June 21 and June 23 through four separate wallet-draining events. According to EMURGO, three attacks were carried out by external threat actors, while the fourth involved an emergency transfer initiated by the company itself. During that intervention, approximately 129 million ADA was moved into a third-party custodial wallet before attackers could gain access. Nevertheless, 16.1 million ADA could not be secured in time. Blockchain intelligence firm Groom Lake reportedly concluded that the primary attacker displayed behavioral and technical characteristics consistent with North Korea's Lazarus Group, although investigators have not officially attributed the attack. Another unrelated attacker was also found to have targeted different wallets during the same period.

Zilliqa Vulnerability Highlights Widespread Cryptographic Implementation Risks

The SecondFi announcement coincided with the disclosure of a similar cryptographic weakness affecting Zilliqa's Ledger hardware wallet application. Researchers revealed that the flaw had remained undetected since 2019 and could also allow private key reconstruction after collecting multiple blockchain signatures. Although the technical mechanisms differed, both vulnerabilities originated from flawed nonce generation during transaction signing. Security specialists said the incidents demonstrated that nonce-generation errors remain a significant and actively exploitable risk across blockchain wallet software. The simultaneous disclosure of structurally similar vulnerabilities in both SecondFi and Zilliqa suggests that cryptographic implementation flaws may be more widespread than previously recognized across the blockchain ecosystem. SecondFi's closure carries broader implications because EMURGO is one of Cardano's three founding organizations. The wallet had replaced Yoroi, which served more than one million users over nearly eight years before being rebranded as SecondFi earlier this year.

EMURGO Develops Zero-Knowledge Recovery Portal for August Release

EMURGO stated it is developing a zero-knowledge proof-based recovery portal, currently undergoing third-party audits, with an expected release in August. Additional wallet migration tools are also planned to help unaffected users transfer their ADA to alternative wallets. A verification portal will allow users to determine whether their wallet addresses were among the 374 compromised. The company emphasized that users who relied on Ledger or Trezor hardware wallets for transaction signing were not affected because the vulnerability existed solely within SecondFi's Android software rather than the hardware wallet firmware. EMURGO confirmed its efforts will focus exclusively on recovering assets for affected users through a dedicated recovery team, although no reimbursement timeline has been announced.

FAQ

What caused the SecondFi security breach in June?

The breach resulted from a cryptographic flaw in SecondFi's Android application update released on June 8. The app generated transaction signature nonces using only public transaction information while excluding required secret key material, allowing attackers to reconstruct users' private keys directly from publicly visible blockchain data.

How much cryptocurrency was stolen from SecondFi wallets?

16.1 million ADA was stolen from 374 user wallets between June 21 and June 23. The stolen assets were valued at approximately $2.4 million at the time of the incident and approximately $2.8 million based on ADA prices as of July 22.

When will EMURGO release the recovery portal for affected SecondFi users?

EMURGO stated the zero-knowledge proof-based recovery portal is currently undergoing third-party audits with an expected release in August. The company has not announced a specific reimbursement timeline for affected users.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments