SecondFi has updated its investigation into a security incident affecting its Cardano wallet service. The probe was commissioned by EMURGO and carried out by independent blockchain forensic firm Groom Lake. According to Foresight News, the findings indicate two separate attackers were involved: the primary attacker used advanced techniques with some indicators overlapping known Lazarus Group activity, while a second attacker acted independently through different wallet addresses.
The company said the root cause was a cryptographic flaw in wallet software used to generate per-transaction signatures, which could theoretically allow an attacker to derive private key material from public on-chain data. The flawed code had previously been published without authorization to a public GitHub repository, and SecondFi said it continues to assess the matter and has cooperated with authorities.
The vulnerability has been fixed, and new wallets created with the patched version are not affected. SecondFi said it will close SecondFi and Yoroi wallets. For asset recovery, the company is developing a zero-knowledge proof-based recovery tool expected in August 2026, and it plans to introduce a wallet export feature before then so users can move assets to other wallets.
SecondFi previously said the incident involved four fund outflows, with three carried out by external attackers, resulting in about 16 million ADA being transferred from 374 addresses. It also said it moved about 129 million ADA to an independent third-party custodian for safekeeping.