Svmuu News: SecondFi, a wallet in the Cardano ecosystem, stated that approximately 16.1 million ADA—worth about $2.6 million—were stolen due to an encryption flaw in the wallet software, and the platform will gradually shut down SecondFi and Yoroi wallet services. The incident affected 374 wallets.
SecondFi stated that an independent investigation by blockchain intelligence firm Groom Lake identified the attacker as a sophisticated external actor and found indicators potentially linked to North Korea’s Lazarus Group, though attribution has not yet been confirmed.
SecondFi is developing a zero-knowledge proof-based recovery tool to help affected users recover their assets while limiting the information they need to share. The tool is still in testing and will undergo a third-party audit prior to its scheduled release in August.
SecondFi is also preparing a wallet export feature that will allow users to migrate their assets to other services. The platform has not announced a direct compensation plan, nor has it specified whether it will use its own funds to compensate users.