SecondFi has announced it is shutting down the project following an attack in which hackers stole approximately 16.1 million ADA, worth around $2.6M. The incident took place between June 21 and June 23 and affected 374 wallets. The company said it has already fixed the vulnerability that led to the breach but has decided not to continue developing the service.
According to the findings of its internal investigation, SecondFi identified a flaw in its transaction-signing mechanism. Under certain conditions, the bug allowed attackers to use publicly available blockchain data to reconstruct part of the data related to private keys.
An independent investigation commissioned by EMURGO and carried out by Groom Lake concluded that the main attack was orchestrated by an external attacker with significant technical expertise and resources. According to the investigators, some indicators resemble activity previously linked to the North Korean Lazarus group, although the investigation has not yet reached a final conclusion.
Investigators also identified a second attacker. Based on the available evidence, this individual was not connected to the main breach and compromised a separate group of wallets during the same period.
Company Response to the Attack and Future Plans
The company has released an update to fix the vulnerability. Wallets created after the patch are no longer considered vulnerable. Even so, the team has decided to shut down the project entirely.
The team is now focused on helping users regain access to their assets and withdraw them securely. In August 2026, SecondFi plans to release a recovery tool that uses zero-knowledge proofs. The solution is currently undergoing testing and an external security audit ahead of its release.
The company also plans to enable wallet exports in early August, allowing users to transfer their assets to other services.
