SecondFi to Shut Down After Flaw Exposes Private Keys

SecondFi to Shut Down After Flaw Exposes Private Keys, 16.1M ADA Stolen

Last Updated:
SecondFi to Shut Down After Flaw Exposes Private Keys
Google News

Get our latest news first. Add us as your Preferred Source on Google and tap "Star" to prioritize our updates.

  • SecondFi will not resume normal operations after a flaw exposed 374 Cardano wallets.
  • Attackers stole 16.1 million ADA worth $2.6 million from affected wallets.
  • SecondFi shifts to recovery and migration as users question the delayed timeline.

SecondFi said it will not resume normal operations after its investigation identified a deterministic nonce derivation flaw in its software signer that exposed private-key material through public Cardano transaction data. According to an official report, the breach affected 374 wallets between June 21 and June 23, enabling attackers to steal 16.1 million ADA worth $2.6 million.

However, the incident did not compromise Cardano’s blockchain. Instead, investigators traced the failure to wallet software and its handling of Ed25519 signatures.

Flawed Signing Logic Turned Public Data Into Private Keys

According to BlockSec, the affected software generated a signing nonce using only the public transaction message. By contrast, secure implementations combine that message with secret key material.

As a result, once a user signed and broadcast a transaction, an attacker could reconstruct the nonce from publicly available data. The attacker could then solve the signature equation and recover the address-level private key.

The vulnerability affected versions 10.0.3 through 10.0.6, while version 10.0.6.2 contained the correction. Nevertheless, addresses previously exposed through the flawed software still require migration to newly generated keys.

Simply importing the same seed phrase into the corrected software does not eliminate the earlier exposure. Therefore, affected users must transfer their assets to wallets secured by fresh keys.

Meanwhile, EMURGO hired blockchain intelligence firm Groom Lake to investigate the theft. The inquiry identified one sophisticated operation and a second attacker using a separate group of wallets.

Because the two sets of affected addresses did not overlap, investigators concluded that separate actors had independently exploited the vulnerability. Some indicators also resembled activity previously linked to the Lazarus Group.

However, investigators have not confirmed any attribution. Separately, SecondFi said a copy of the flawed code appeared in a public GitHub repository without authorization.

Recovery Efforts Face Delays as Users Await Next Steps 

Following its decision to end normal operations, SecondFi is focusing its remaining resources on asset recovery, wallet migration, and cooperation with authorities.

As part of that process, SecondFi is testing a zero-knowledge recovery tool. The system would allow affected users to prove wallet ownership while limiting the personal information they disclose.

However, the tool must pass an independent audit before its planned August 2026 release. SecondFi also expects to introduce wallet-export functionality in early August, allowing users to transfer assets to other wallets.

Meanwhile, some users have criticized the extended recovery timeline. Earlier guidance indicated that the process could begin within two weeks after security testing and reviews were completed.

Nearly a month later, however, the recovery tool remains under development. Consequently, affected users are still waiting for a confirmed process to reclaim or migrate their assets.

During the initial response, the team transferred about 129 million ADA to an independent custodian before attackers could access those funds. Nevertheless, the latest update did not provide a reimbursement timetable or explain how unrecovered losses would be covered.

Related: Cardano Price Prediction: Can SecondFi’s Recovery Plan Pull ADA Out Of Its Slump?

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.