SecondFi security incident linked to Lazarus Group; asset recovery tool to launch in August 2026

iconChainthink
Share
AI summary iconSummary
SecondFi confirmed a security breach traced to an attack linked to the Lazarus Group, according to Groom Lake’s investigation. A vulnerability in the wallet software allowed private keys to be derived from public chain data. SecondFi has patched the issue and is developing a zero-knowledge asset recovery tool, scheduled for August 2026. A wallet export feature will enable users to transfer their assets. The breach resulted in three attacks, with 16 million ADA stolen from 374 addresses. SecondFi has moved 129 million ADA to a custodian. Digital asset news underscores the ongoing risks in the space.

ChainThink reports that on July 22, SecondFi disclosed that its security incident investigation was commissioned by EMURGO and conducted by the independent blockchain forensics firm Groom Lake.

The investigation found that the incident involved two separate attackers; the primary attacker shares some indicators with known activities of the North Korean Lazarus Group, and further assessment is ongoing. The second attacker used different wallet addresses, with evidence independent of the primary attack.

SecondFi stated that the root cause of the incident was a cryptographic flaw in the wallet software during the generation of transaction signatures, which theoretically could allow attackers to derive the private key material of affected wallets from on-chain data.

The related flawed code was previously unauthorizedly released to a public GitHub repository; SecondFi states it is continuously evaluating the situation and cooperating with regulatory authorities in their investigation. The vulnerability has now been patched, and newly created wallets using the patched version are unaffected.

SecondFi will shut down SecondFi and Yoroi wallets and is developing a zero-knowledge proof-based asset recovery tool, expected to be released in August 2026;

Prior to this, a wallet export feature will be launched, allowing users to migrate their assets to other wallets.

Previously disclosed information showed that there were four fund transfers in total, with three carried out by external attackers, resulting in approximately 16 million ADA being transferred from 374 addresses;

SecondFi has transferred approximately 129 million ADA to an independent third-party custodian.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.