An update regarding the recent security incident involving SecondFi
What happened to SecondFi
Between June 21st and 23rd, SecondFi experienced a security incident that resulted in approximately 16.1 million ADA (~$2.6 million) being stolen from 374 wallets. We want to provide users with a transparent update based on the information currently available.
An independent investigation
EMURGO engaged Groom Lake, an independent forensic investigation / blockchain intelligence provider to assist with tracing and evidentiary analysis and they reviewed the incident using primary technical evidence, including code, code history, and public blockchain data.
What the investigation indicates to date:
1. Attack from an external actor: linked to high-volume addresses employing advanced tradecraft: @0xGroomLake indicates that the primary operation behind the unauthorised transfers was sophisticated, external, and well-funded, with indicators consistent with activity by a professional, state-aligned threat actor. Certain indicators are being assessed for potential overlap with known DPRK-linked threat activity of Lazarus Group.
2. Two separate attackers: Groom Lake also identified activity by a second party that appears, based on current evidence, to be separate from the primary operation and to have affected a different set of wallets during the same window. No overlap in affected wallets has been identified to date.
The root cause: A cryptographic flaw
The root cause was a highly subtle flaw in how the wallet software generated per-transaction signatures. In simplified terms, a value that should have been derived from secret information could, under certain conditions, be computed from public transaction data. This could enable affected private key material to be derived from information visible on the public blockchain.
This cryptographic flaw was also visible in a copy of the relevant code that had been published without authorisation to a public GitHub repository. We are continuing to assess the circumstances surrounding the publication and are cooperating with the relevant authorities.
Fix and winding down of SecondFi
The flaw has been patched, and new wallets created with the corrected software are not known to be affected by this issue. However, given the gravity of this event and as previously announced, we have made the difficult decision to wind down SecondFi and Yoroi wallet.
Asset recovery and safe migration
Our current priority is supporting affected users, assisting recovery efforts, and enabling users to move assets securely.
1. Recovery tool: A secure recovery tool using zero-knowledge (ZK) proofs is being developed. The portal is designed to allow users to initiate the process directly while limiting the information required to do so. The tool is currently in testing, and we are engaging a specialist third-party auditor to review it before its anticipated release in August 2026.
2. Safe migration: In the meantime, we are preparing wallet export functionality designed to allow users to migrate their assets to a wallet of their choice. We anticipate releasing this by early August 2026.
Please follow our official channels for further updates.
Important Security Reminder
SecondFi will NEVER request private keys, recovery phrases, or wallet credentials, and we will never DM you first. Do not trust any checker, link, or account outside our official channels:
▪️ X accounts: @secondfiapp and @secondfi_jp
▪️ Support portal: https://t.co/bKfl8SK9D2