Pluang
SecondFi Wallet Shutdown After $2.6M Theft Due to Signing Flaw
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
SecondFi, a Cardano wallet, announced its shutdown after a security breach allowed attackers to steal 16.1 million ADA, valued at approximately $2.6 million. The attack exploited a signing flaw in the wallet's software, which was introduced in a June 8 update. This flaw enabled the private keys of 374 user wallets to be exposed through public blockchain data. An independent investigation suggested links to North Korea's Lazarus Group, although no formal attribution has been confirmed. Users are currently awaiting recovery tools, which are expected to be released in August. The incident marks a significant failure in Cardano's application-layer security, raising concerns about similar vulnerabilities in other blockchain systems. SecondFi will not resume operations, and no reimbursement plan has been announced.
Key Points: • SecondFi wallet shutdown followed a $2.6 million theft due to a signing flaw. • The flaw exposed private keys of 374 wallets, allowing attackers to drain funds. • Recovery tools for affected users are under development and expected in August.