CoinTrust

Cardano Wallet SecondFi to Shut Down After $2.4M Security Breach

secondfi

SecondFi, the Cardano wallet introduced in April 2026 as the successor to EMURGO’s Yoroi platform, has announced that it will permanently cease operations after a critical security flaw led to the theft of 16.1 million ADA from 374 user wallets. The stolen assets were valued at about $2.4 million when the incident occurred in June and approximately $2.8 million based on ADA prices as of July 22, 2026.

Parallel Zilliqa vulnerability raises broader concerns over blockchain wallet security

The vulnerability originated from an Android application update released on June 8. The flaw caused every transaction signed through the affected application to expose enough information for attackers to reconstruct users’ private keys from publicly available blockchain data. Security experts noted that, because blockchain records are immutable, the compromised keys remain permanently recoverable even after software updates and the platform’s closure.

EMURGO confirmed that SecondFi will not resume operations and said its efforts will focus exclusively on recovering assets for affected users through a dedicated recovery team, although no reimbursement timeline has been announced.

Permanent Key Exposure Triggered Shutdown

The flaw stemmed from the wallet’s implementation of Cardano’s extended Ed25519 digital signature scheme. Normally, each transaction signature relies on a unique nonce generated using both transaction data and secret key material stored on the user’s device. This approach ensures that signatures cannot reveal the underlying private key.

However, SecondFi’s Android application generated the nonce using only public transaction information while excluding the required secret component. Cybersecurity researchers later confirmed that this implementation mistake allowed anyone monitoring Cardano‘s blockchain to calculate users’ private keys directly from transaction signatures.

Independent researchers demonstrated the vulnerability by reconstructing private keys solely from publicly available blockchain records. Security analysts also indicated that the implementation represented one of the most severe cryptographic failures seen in a production cryptocurrency wallet, exceeding the impact of several early Bitcoin wallet vulnerabilities.


Because the compromised information is embedded in permanent blockchain records, EMURGO warned users that restoring an affected recovery phrase into another Cardano wallet would not eliminate the risk. Instead, users must completely abandon compromised wallet addresses and generate entirely new keys.

Multiple Attacks Over Two Days

The exploit occurred between June 21 and June 23 through four separate wallet-draining events. According to EMURGO, three attacks were carried out by external threat actors, while the fourth involved an emergency transfer initiated by the company itself. During that intervention, approximately 129 million ADA was moved into a third-party custodial wallet before attackers could gain access. Nevertheless, 16.1 million ADA could not be secured in time.

Blockchain intelligence firm Groom Lake reportedly concluded that the primary attacker displayed behavioral and technical characteristics consistent with North Korea’s Lazarus Group, although investigators have not officially attributed the attack. Another unrelated attacker was also found to have targeted different wallets during the same period.

Security Concerns Extend Beyond Cardano

The SecondFi announcement coincided with the disclosure of a similar cryptographic weakness affecting Zilliqa’s Ledger hardware wallet application. Researchers revealed that the flaw had remained undetected since 2019 and could also allow private key reconstruction after collecting multiple blockchain signatures.

Although the technical mechanisms differed, both vulnerabilities originated from flawed nonce generation during transaction signing. Security specialists said the incidents demonstrated that nonce-generation errors remain a significant and actively exploitable risk across blockchain wallet software.

The simultaneous disclosure of structurally similar vulnerabilities in both SecondFi and Zilliqa suggests that cryptographic implementation flaws may be more widespread than previously recognized across the blockchain ecosystem.

SecondFi’s closure also carries broader implications because EMURGO is one of Cardano‘s three founding organizations alongside the Cardano Foundation and Input Output Global. The wallet had replaced Yoroi, which served more than one million users over nearly eight years before being rebranded as SecondFi earlier this year.

Recovery Measures Under Development

EMURGO stated that it is developing a zero-knowledge proof-based recovery portal, currently undergoing third-party audits, with an expected release in August. Additional wallet migration tools are also planned to help unaffected users transfer their ADA to alternative wallets, while a verification portal will allow users to determine whether their wallet addresses were among the 374 compromised.

The company emphasized that users who relied on Ledger or Trezor hardware wallets for transaction signing were not affected because the vulnerability existed solely within SecondFi‘s Android software rather than the hardware wallet firmware.

The incident has intensified scrutiny of self-custody wallet security, highlighting that while users may control their own private keys, the safety of those assets ultimately depends on the correctness of the cryptographic software responsible for generating transaction signatures.

Exit mobile version