ChainThink reports that on July 22, SecondFi disclosed that its security incident investigation was commissioned by EMURGO and conducted by the independent blockchain forensics firm Groom Lake.
The investigation found that the incident involved two separate attackers; the primary attacker shares some indicators with known activities of the North Korean Lazarus Group, and further assessment is ongoing. The second attacker used different wallet addresses, with evidence independent of the primary attack.
SecondFi stated that the root cause of the incident was a cryptographic flaw in the wallet software during the generation of transaction signatures, which theoretically could allow attackers to derive the private key material of affected wallets from on-chain data.
The related flawed code was previously unauthorizedly released to a public GitHub repository; SecondFi states it is continuously evaluating the situation and cooperating with regulatory authorities in their investigation. The vulnerability has now been patched, and newly created wallets using the patched version are unaffected.
SecondFi will shut down SecondFi and Yoroi wallets and is developing a zero-knowledge proof-based asset recovery tool, expected to be released in August 2026;
Prior to this, a wallet export feature will be launched, allowing users to migrate their assets to other wallets.
Previously disclosed information showed that there were four fund transfers in total, with three carried out by external attackers, resulting in approximately 16 million ADA being transferred from 374 addresses;
SecondFi has transferred approximately 129 million ADA to an independent third-party custodian.

