Sign up
Subscribe
Home / news / SecondFi shuts down after a $2.4 million theft from its users
news

SecondFi shuts down after a $2.4 million theft from its users

SecondFi shuts down after a $2.4 million theft from its users

Cryptocurrency wallet SecondFi is winding down after an attack drained $2.4 million from users, with the company saying it has already fixed the flaw that enabled the theft. For PSPs and other high-risk payment operators, the part that matters is simple: wallet security failures still turn into operational shutdowns, not just incident reports.

  1. The company said on Wednesday, July 22, that it had addressed the vulnerability that allowed the theft of 16.1 million in ADA last month and had secured another 129 million ADA before hackers could reach it.
  2. “However, given the gravity of this event and as previously announced, we have made the difficult decision to wind down SecondFi and Yoroi wallet,” the company said. The shutdown is not just about patching a bug; it is the business ending after the incident.
  3. SecondFi said the root cause was a “highly subtle flaw in how the wallet software generated per-transaction signatures.” In its own wording, a value that should have come from secret information could, under certain conditions, be computed from public transaction data, which could let affected private key material be derived from blockchain-visible information.
  4. Groom Lake, the intelligence firm commissioned by blockchain company EMURGO, said the main attacker was “external, and well-funded, with indicators consistent with activity by a professional, state-aligned threat actor,” and that there are indications suggesting involvement by North Korea’s Lazarus Group.
  5. SecondFi said it expects wallet export tools to be ready early next month, with a zero-knowledge recovery portal rolling out later in August. The attack sits inside a run of recent exploits at digital asset platforms this year, even if it was smaller than the April exploit of Kelp DAO, which saw roughly $292 million stolen.

For high-risk operators, the interesting detail is not the branding around the incident but the mechanics: once signature generation fails, key material can become recoverable from public data. That is the kind of failure that forces a full wind-down, not just a postmortem.

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!