Cardano wallet SecondFi is winding down after attackers exploited a flaw in its transaction signing software to steal 16.1 million ADA, worth roughly $2.4 million, from 374 wallets.
The service, which replaced EMURGO’s Yoroi wallet, said it will not resume normal operations despite patching the vulnerability.and at the time securing 129 million ADA before attackers could reach the funds.
The flaw allowed attackers to derive private key material from transaction data visible on the Cardano blockchain, SecondFi said. The Cardano network itself was not compromised, and hardware wallet users were not affected.
Groom Lake, the blockchain intelligence firm hired by EMURGO, found that the main attacker was sophisticated and well-funded. Some indicators point to North Korea’s Lazarus Group, though no attribution has been confirmed, the firm said.
A separate attacker targeted another set of wallets during the same period.
SecondFi expects to release wallet export tools in early August and a zero-knowledge recovery portal later that month. EMURGO has funded an asset recovery wallet, but no firm distribution date has been given.
In Q2; TRON's stablecoin dominance rose to 28.7%, USDT supply on TRON hit $89B ATH, $89M in protocol fees (2nd to Hyperliquid), TRX +3%, and deepening institutional & agentic reach.
In Q2; TRON's stablecoin dominance rose to 28.7%, USDT supply on TRON hit $89B ATH, $89M in protocol fees (2nd to Hyperliquid), TRX +3%, and deepening institutional & agentic reach.
In Q2; TRON's stablecoin dominance rose to 28.7%, USDT supply on TRON hit $89B ATH, $89M in protocol fees (2nd to Hyperliquid), TRX +3%, and deepening institutional & agentic reach.
Source
This article is syndicated for educational reading. For the latest updates, visit the original publisher.
Read on coindesk.com