Pluang SecondFi Wallet Shutdown After $2.6M Theft Due to Signing Flaw
Article Content
- •SecondFi wallet shutdown followed a $2.6 million theft due to a signing flaw.
- •The flaw exposed private keys of 374 wallets, allowing attackers to drain funds.
- •Recovery tools for affected users are under development and expected in August.
SecondFi, a Cardano wallet, announced its shutdown after a security breach allowed attackers to steal 16.1 million ADA, valued at approximately $2.6 million. The attack exploited a signing flaw in the wallet's software, which was introduced in a June 8 update. This flaw enabled the private keys of 374 user wallets to be exposed through public blockchain data. An independent investigation suggested links to North Korea's Lazarus Group, although no formal attribution has been confirmed. Users are currently awaiting recovery tools, which are expected to be released in August. The incident marks a significant failure in Cardano's application-layer security, raising concerns about similar vulnerabilities in other blockchain systems. SecondFi will not resume operations, and no reimbursement plan has been announced.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Lazarus Group and SecondFi in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across the Middle East and Africa. This operation involves the use of two newly discovered malware families, NodeRabbit and PollCat, both of which are cross-platform remote…
Social Engineering Campaign Hijacks Microsoft 365 Accounts via Passkey Alerts A social engineering campaign impersonating IT support staff is actively hijacking Microsoft 365 accounts. The attackers use passkey-themed lures to trick users into providing credentials, leading to unauthorized access and data exfiltration. Microsoft Security Research has tracked these intrusions since May 2026…